CVE-2026-82039
Received Received - Intake

SQL Injection in UTMStack Prior to 11.2.16

Vulnerability report for CVE-2026-82039, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType and groupName values that are inserted unsanitized into a native PostgreSQL query via String.format(). Attackers can exploit the GET /api/utm-asset-groups/searchGroupsByFilter endpoint to execute arbitrary SQL with DBA privileges, enabling full database read, data modification, and potential filesystem access.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-03
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
utmstack utmstack to 11.2.16 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-82039 is a SQL injection vulnerability in UTMStack versions before 11.2.16. It exists in the UtmAssetGroupService.searchQueryBuilder() function where user-supplied input for assetType and groupName parameters is inserted directly into a PostgreSQL query without sanitization. This allows authenticated attackers to inject malicious SQL commands through the GET /api/utm-asset-groups/searchGroupsByFilter endpoint.

Detection Guidance

To detect this SQL injection vulnerability in UTMStack, monitor network traffic for suspicious requests to the GET /api/utm-asset-groups/searchGroupsByFilter endpoint. Check for malformed assetType or groupName parameters containing SQL syntax like ' OR 1=1 -- or UNION SELECT. Inspect PostgreSQL logs for queries generated via String.format() with unsanitized inputs.

Impact Analysis

An attacker could exploit this to execute arbitrary SQL commands with database administrator privileges. This could result in full database read access, unauthorized data modification, and potentially filesystem access. The vulnerability requires authentication but allows complete control over the database once exploited.

Compliance Impact

This SQL injection vulnerability could lead to unauthorized database access, allowing attackers to read, modify, or delete sensitive data. For GDPR, this may result in unauthorized data access or breaches, potentially violating confidentiality and integrity requirements. Under HIPAA, exposure of protected health information (PHI) through such attacks could lead to compliance violations and data breaches.

Mitigation Strategies

Immediately upgrade UTMStack to version 11.2.16 or later to apply the patch that replaces String.format() with parameterized queries. If upgrading is not possible, restrict access to the /api/utm-asset-groups/searchGroupsByFilter endpoint and implement input validation for assetType and groupName parameters.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82039. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart