CVE-2026-82041

MEDIUM CVSS 4.0: 6.5 EPSS 0.44%
Updated Oct 06, 2026
Utmstack
Parameter Value
CVSS 6.5 (MEDIUM)
Affected Versions before 11.2.16
Type CWE-862 (Missing Authorization)
Vendor Utmstack
Public PoC No

UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied before forwarding supplied commands. Any authenticated user, regardless of role, can send arbitrary operating-system commands over gRPC to any connected agent, resulting in command execution on monitored endpoints where agent processes commonly run as root or SYSTEM.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0

Vulnerable Products

utmstack:utmstack