CVE-2026-82042 CRITICAL

CVE-2026-82042: UTMStack < 11.2.16 Authentication Bypass via InternalApiKeyFilter

Vendor Utmstack
Product UTMStack
Weakness CWE-306 · Missing auth
Published October 2, 2026
Last update October 4, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable value, which the InternalApiKeyFilter accepts for any endpoint without path restriction, constant-time comparison, rate limiting, or audit logging. Attackers who obtain the key value can authenticate without a user account or JWT to create accounts, manage users, exfiltrate data, and modify security rules.

Key dates

02Disclosure timeline

October 2, 2026 CVE published
October 4, 2026 Record updated

Related vulnerabilities

04Related CVE