Account Enumeration Vulnerability in UTMStack by UTMStack
CVE-2026-82043

6.9MEDIUM

Key Information:

Vendor

Utmstack

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-82043?

UTMStack versions before 11.2.16 are susceptible to an account enumeration vulnerability. This issue enables unauthorized attackers to identify registered email addresses by analyzing the different HTTP responses returned from the POST /api/account/reset-password/init endpoint. By submitting arbitrary email addresses, attackers can differentiate between valid accounts, indicated by a 200 OK response, and non-registered accounts, which trigger a 500 Internal Server Error response. This vulnerability opens the door for targeted phishing and credential theft attacks, emphasizing the urgency of upgrading to the latest version.

Affected Version(s)

UTMStack 0 < 11.2.16

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adam Nurudini (QwesiRED)
VulnCheck
.