Server-Side Request Forgery in UTMStack Web Application
CVE-2026-82044

6.3MEDIUM

Key Information:

Vendor

Utmstack

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-82044?

A vulnerability in UTMStack allows authenticated attackers to exploit the PdfService.downloadPdf() method through a crafted URL parameter, enabling them to manipulate server requests. This can lead to unauthorized access to internal resources, including backend endpoints and sensitive metadata, which may then be exposed in generated PDF reports. The vulnerability exists in versions before 11.2.16, necessitating immediate updates to ensure system integrity and data protection.

Affected Version(s)

UTMStack 0 < 11.2.16

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adam Nurudini (QwesiRED)
VulnCheck
.