CVE-2026-82041: medium-severity vulnerability in UTMStack
UTMStack < 11.2.16 Missing Authorization via Command WebSocket
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 0.4%
exploitation probability
0.4%top 64% of all CVEs
observed exploitation
nono source reports it
UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied before forwarding supplied commands. Any authenticated user, regardless of role, can send arbitrary operating-system commands over gRPC to any connected agent, resulting in command execution on monitored endpoints where agent processes commonly run as root or SYSTEM.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
Affected products
UTMStack · UTMStackRelated CVEs — UTMStack
In the same product, most dangerous first.
CVE-2026-82042CRITICALUTMStack < 11.2.16 Authentication Bypass via InternalApiKeyFilterEPSS 0.5%CVE-2026-82039HIGHUTMStack < 11.2.16 SQL Injection via searchGroupsByFilterEPSS 0.3%CVE-2026-82045HIGHUTMStack < 11.2.16 JPQL Injection via searchPropertyValuesEPSS 0.3%CVE-2026-82044MEDIUMUTMStack < 11.2.16 Server-Side Request Forgery via downloadPdfEPSS 0.3%CVE-2026-82043MEDIUMUTMStack < 11.2.16 Account Enumeration via Password Reset EndpointEPSS 0.2%CVE-2026-82040MEDIUMUTMStack < 11.2.16 SSRF via IdentityProviderServiceEPSS 0.2%