Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

UTMStack’s seven-CVE disclosure includes a serious authorization flaw in its incident-command WebSocket: in affected versions, an authenticated user could send operating-system commands to connected agents without the handler checking for an administrator role. CVE-2026-82041 is rated 9.9 under CVSS 3.1, but 6.5 under CVSS 4.0. The reported affected versions are those before UTMStack 11.2.16; the vendor’s October 1, 2026 release is identified as containing fixes for the seven CVEs.

What the command WebSocket flaw allows

CVE-2026-82041 concerns the STOMP destination /command/{hostname}. In vulnerable versions, that destination reaches UTMIncidentCommandWebsocket.processCommand(), which lacked both role checks and a command allowlist. Rapid7’s record describes the flaw as requiring an authenticated account; it is therefore a missing-authorization issue, not an entirely unauthenticated endpoint.

Because commands can be sent to connected agents, the potential consequences are not limited to the UTMStack server. The vulnerability’s severity score describes technical impact under a scoring framework; it does not establish that an attack occurred or indicate how likely one is.

All seven reported CVEs

The following CVSS 3.1 scores are from ThreatAft’s October 3, 2026 cluster report. The vendor’s security commit supplies the technical fix descriptions. A CVSS score is a severity metric, not an incident count or breach probability.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
CVE Reported issue CVSS 3.1
CVE-2026-82041 Missing authorization in the command WebSocket; authenticated users could submit commands to agents. 9.9
CVE-2026-82042 Internal-key authentication bypass. 9.8
CVE-2026-82039 SQL injection in asset-group search. 8.8
CVE-2026-82044 Server-side request forgery (SSRF) in PDF generation. 7.7
CVE-2026-82045 JPQL injection in network-scan property search. 6.5
CVE-2026-82043 Account enumeration through password reset. 5.3
CVE-2026-82040 SSRF in identity-provider metadata URL validation. 5.0

Why CVE-2026-82041 has two different severity scores

Rapid7 lists CVE-2026-82041 at 9.9 (Critical) under CVSS 3.1 and 6.5 (Medium) under CVSS 4.0. These are scores under different versions of the scoring system, not conflicting reports of two vulnerabilities. When citing the 9.9 figure, identify it as CVSS 3.1; the same Rapid7 record gives 6.5 for CVSS 4.0.

Rapid7’s CVSS 3.1 vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. It records network reachability, low attack complexity, low privileges required, no user interaction, changed scope, and high confidentiality, integrity, and availability impact. The required authenticated account is consistent with the vector’s low-privileges-required rating.

Which UTMStack versions are affected, and what fixes them?

The reported affected range is UTMStack versions before 11.2.16. The vendor published v11.2.16 on October 1, 2026. Its associated security commit explicitly identifies fixes for seven disclosed CVEs numbered 82039 through 82045. The release page’s summary emphasizes alert changes rather than listing the security fixes, so the commit and the cluster report provide the connection between that release and the vulnerabilities.

Operators should verify their installed version and upgrade to 11.2.16 or a later release that includes these fixes. The available information does not establish that every later build necessarily contains them; confirm the fixes in the release notes or vendor guidance for the version you plan to install.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the vendor changed

  • CVE-2026-82041: The command WebSocket handler now requires ROLE_ADMIN.
  • CVE-2026-82039: The asset-group native search query is parameterized, and sort columns are allowlisted.
  • CVE-2026-82045: The searched value in the network-scan property query is bound rather than inserted into the query.
  • CVE-2026-82040: Identity-provider metadata URLs are restricted to public HTTP(S) hosts. Literal IP addresses and resolutions to local addresses are rejected, and redirects are disallowed.
  • CVE-2026-82044: PDF report URLs are constrained to relative paths under known print/export prefixes.
  • CVE-2026-82043: Password-reset initiation returns a generic successful response with an empty body, preventing callers from distinguishing unknown accounts.
  • CVE-2026-82042: Internal-key authentication is limited to an allowlist of machine-to-machine routes, and accepted key use is recorded in an audit log. The commit retains constant-time key comparison and supports the optional INTERNAL_KEY_ALLOWED_CIDRS setting; the route allowlist is always applied.

What operators should do

  1. Identify the deployed version. Check the version of each UTMStack instance, including any separate or standby deployments that could still be exposed.
  2. Upgrade to a fixed release. Move to 11.2.16 or a later version whose release information confirms these fixes, using the normal update procedure for your deployment.
  3. Review activity for signs of misuse. Examine command/WebSocket activity and administrative API access for unusual accounts, times, destinations, or actions. This is prudent response guidance; the vendor commit describes code changes, not a complete incident-response procedure.
  4. Review internal-key handling. Consider whether the INTERNAL_KEY value has been exposed or handled insecurely, and review accepted-key-use audit records. The optional CIDR restriction can further limit where internal-key authentication is accepted, but it does not replace the built-in route allowlist.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is known about exploitation

Rapid7’s record, dated October 2, 2026, said CVE-2026-82041 was not listed in CISA’s Known Exploited Vulnerabilities catalog at the time checked. ThreatAft’s October 3 cluster report said it tracked no public exploit and also reported no KEV listing. These are dated status snapshots, not proof that the flaws have never been exploited or that their status has not changed since.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.