Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-82041— UTMStack < 11.2.16 Missing Authorization via Command WebSocket

Quick assessment

Affected
UTMStack UTMStack
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

UTMStack 11.2.16 之前的版本中存在一个授权缺失漏洞,位于 方法中,该方法处理映射到 STOMP 目的地 的请求。在向连接的代理转发传入的命令之前,未进行角色检查或命令白名单验证。任何已认证用户,无论其角色如何,都可以通过 gRPC 向任何已连接的代理发送任意操作系统命令,从而在监控端点上执行命令,而代理进程通常以 root 或 SYSTEM 权限运行。

CVSS 9.9 · Critical
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-82041

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
UTMStack < 11.2.16 Missing Authorization via Command WebSocket
Source: CVE Program / CVE List V5
Vulnerability Description
UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied before forwarding supplied commands. Any authenticated user, regardless of role, can send arbitrary operating-system commands over gRPC to any connected agent, resulting in command execution on monitored endpoints where agent processes commonly run as root or SYSTEM.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
UTMStack UTMStack 0 ~ 11.2.16 -

II. Public POCs for CVE-2026-82041

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-82041

请登录查看更多情报信息。

Other References for CVE-2026-82041 (3)

Same Patch Batch · UTMStack · 2026-10-02 · 7 CVEs total

CVE-2026-82042 9.8 CRITICAL UTMStack < 11.2.16 Authentication Bypass via InternalApiKeyFilter
CVE-2026-82039 8.8 HIGH UTMStack < 11.2.16 SQL Injection via searchGroupsByFilter
CVE-2026-82044 7.7 HIGH UTMStack < 11.2.16 Server-Side Request Forgery via downloadPdf
CVE-2026-82045 6.5 MEDIUM UTMStack < 11.2.16 JPQL Injection via searchPropertyValues
CVE-2026-82043 5.3 MEDIUM UTMStack < 11.2.16 Account Enumeration via Password Reset Endpoint
CVE-2026-82040 5.0 MEDIUM UTMStack < 11.2.16 SSRF via IdentityProviderService

IV. Related Vulnerabilities

V. Comments for CVE-2026-82041

No comments yet


Leave a comment