Account Enumeration Vulnerability in UTMStack by UTMStack
CVE-2026-82043
6.9MEDIUM
What is CVE-2026-82043?
UTMStack versions before 11.2.16 are susceptible to an account enumeration vulnerability. This issue enables unauthorized attackers to identify registered email addresses by analyzing the different HTTP responses returned from the POST /api/account/reset-password/init endpoint. By submitting arbitrary email addresses, attackers can differentiate between valid accounts, indicated by a 200 OK response, and non-registered accounts, which trigger a 500 Internal Server Error response. This vulnerability opens the door for targeted phishing and credential theft attacks, emphasizing the urgency of upgrading to the latest version.
Affected Version(s)
UTMStack 0 < 11.2.16
