Vulnerability Description
UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable value, which the InternalApiKeyFilter accepts for any endpoint without path restriction, constant-time comparison, rate limiting, or audit logging. Attackers who obtain the key value can authenticate without a user account or JWT to create accounts, manage users, exfiltrate data, and modify security rules.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/UTMStack/UTMStack/releases/tag/v11.2.16
- https://github.com/utmstack/UTMStack/commit/4e7a727c3b8d8e2ad020d3b4f982a6d085db
- https://www.vulncheck.com/advisories/utmstack-authentication-bypass-via-internal
FAQ
What is CVE-2026-82042?
CVE-2026-82042 is a vulnerability with a CVSS score of 9.8 (CRITICAL). UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the I...
How severe is CVE-2026-82042?
CVE-2026-82042 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-82042?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.