Authentication Bypass Vulnerability in UTMStack by UTMStack
CVE-2026-82042
9.3CRITICAL
What is CVE-2026-82042?
A critical vulnerability exists in UTMStack prior to version 11.2.16, which enables remote attackers to bypass authentication through improper handling of the Utm-Internal-Key header. The InternalApiKeyFilter does not enforce strict path limitations or utilize secure methods for validating this key, allowing attackers with knowledge of the key to gain full administrative access to the API without the need for user accounts or JSON Web Tokens (JWT). This access can lead to severe consequences, including unauthorized account creation, user management, data exfiltration, and modification of security settings, compromising the integrity and confidentiality of the affected systems.
Affected Version(s)
UTMStack 0 < 11.2.16
