Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-82042— UTMStack < 11.2.16 Authentication Bypass via InternalApiKeyFilter

Quick assessment

Affected
UTMStack UTMStack
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 UTMStack 11.2.16 版本之前存在一个身份验证绕过漏洞,远程攻击者可以通过提供一个与 环境变量值匹配的 请求头,来获取完整的管理 API 访问权限。 过滤器在未对路径进行限制、未采用恒定时间比较、未实施速率限制、也未记录审计日志的情况下,接受了该请求头。攻击者在获取该密钥值后,可以在不使用用户账户或 JWT(JSON Web Token)的情况下完成身份验证,从而创建账户、管理用户、窃取数据以及修改安全规则。

CVSS 9.8 · Critical
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-82042

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
UTMStack < 11.2.16 Authentication Bypass via InternalApiKeyFilter
Source: CVE Program / CVE List V5
Vulnerability Description
UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable value, which the InternalApiKeyFilter accepts for any endpoint without path restriction, constant-time comparison, rate limiting, or audit logging. Attackers who obtain the key value can authenticate without a user account or JWT to create accounts, manage users, exfiltrate data, and modify security rules.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
UTMStack UTMStack 0 ~ 11.2.16 -

II. Public POCs for CVE-2026-82042

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-82042

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-82042 (1)

Vendor Pages for CVE-2026-82042 (1)

Same Patch Batch · UTMStack · 2026-10-02 · 7 CVEs total

CVE-2026-82041 9.9 CRITICAL UTMStack < 11.2.16 Missing Authorization via Command WebSocket
CVE-2026-82039 8.8 HIGH UTMStack < 11.2.16 SQL Injection via searchGroupsByFilter
CVE-2026-82044 7.7 HIGH UTMStack < 11.2.16 Server-Side Request Forgery via downloadPdf
CVE-2026-82045 6.5 MEDIUM UTMStack < 11.2.16 JPQL Injection via searchPropertyValues
CVE-2026-82043 5.3 MEDIUM UTMStack < 11.2.16 Account Enumeration via Password Reset Endpoint
CVE-2026-82040 5.0 MEDIUM UTMStack < 11.2.16 SSRF via IdentityProviderService

IV. Related Vulnerabilities

V. Comments for CVE-2026-82042

No comments yet


Leave a comment