Missing Authorization Vulnerability in UTMStack by UTMStack
CVE-2026-82041
6.5MEDIUM
What is CVE-2026-82041?
UTMStack versions before 11.2.16 are susceptible to a missing authorization vulnerability located in the UTMIncidentCommandWebsocket.processCommand() function. This flaw arises from the lack of a proper role check or command allowlist, enabling any authenticated user to execute arbitrary operating system commands over gRPC on any connected agent. This results in potential command execution on monitored endpoints where agent processes typically operate with elevated privileges, such as root or SYSTEM.
Affected Version(s)
UTMStack 0 < 11.2.16
