CVE-2026-82042
Received Received - Intake

Authentication Bypass in UTMStack via Internal Key Header

Vulnerability report for CVE-2026-82042, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable value, which the InternalApiKeyFilter accepts for any endpoint without path restriction, constant-time comparison, rate limiting, or audit logging. Attackers who obtain the key value can authenticate without a user account or JWT to create accounts, manage users, exfiltrate data, and modify security rules.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
utmstack utmstack to 11.2.16 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

UTMStack before version 11.2.16 has an authentication bypass flaw. Attackers can gain full admin API access by using a valid Utm-Internal-Key header that matches the INTERNAL_KEY environment variable. This header is accepted for any endpoint without proper restrictions, allowing unauthorized actions like account creation, data exfiltration, and security rule modifications.

Impact Analysis

If exploited, attackers can create admin accounts, steal sensitive data, or alter security configurations without detection. This could lead to complete system compromise, unauthorized access to networks, and potential data breaches affecting users and organizations relying on UTMStack.

Compliance Impact

This vulnerability could violate compliance requirements by enabling unauthorized access to sensitive data, leading to potential breaches of GDPR, HIPAA, or other regulations. Organizations using affected UTMStack versions may face legal penalties, loss of certification, or reputational damage due to inadequate security controls.

Mitigation Strategies

Immediately upgrade UTMStack to version 11.2.16 or later to address the authentication bypass vulnerability. Ensure the INTERNAL_KEY environment variable is rotated and no longer exposed in logs or configurations. Review all API endpoints for unauthorized access and audit existing accounts for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82042. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart