Authentication Bypass Vulnerability in UTMStack by UTMStack
CVE-2026-82042

9.3CRITICAL

Key Information:

Vendor

Utmstack

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-82042?

A critical vulnerability exists in UTMStack prior to version 11.2.16, which enables remote attackers to bypass authentication through improper handling of the Utm-Internal-Key header. The InternalApiKeyFilter does not enforce strict path limitations or utilize secure methods for validating this key, allowing attackers with knowledge of the key to gain full administrative access to the API without the need for user accounts or JSON Web Tokens (JWT). This access can lead to severe consequences, including unauthorized account creation, user management, data exfiltration, and modification of security settings, compromising the integrity and confidentiality of the affected systems.

Affected Version(s)

UTMStack 0 < 11.2.16

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adam Nurudini (QwesiRED)
VulnCheck
.