CVE-2026-82042 PUBLISHED

UTMStack < 11.2.16 Authentication Bypass via InternalApiKeyFilter

Assigner: VulnCheck
Reserved: 27.08.2026 Published: 02.10.2026 Updated: 02.10.2026

UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable value, which the InternalApiKeyFilter accepts for any endpoint without path restriction, constant-time comparison, rate limiting, or audit logging. Attackers who obtain the key value can authenticate without a user account or JWT to create accounts, manage users, exfiltrate data, and modify security rules.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor UTMStack
Product UTMStack
Versions Default: unaffected
  • affected from 0 to 11.2.16 (excl.)

Credits

  • Adam Nurudini (QwesiRED) finder
  • VulnCheck coordinator

References

Problem Types

  • Missing Authentication for Critical Function CWE