Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-82044— UTMStack < 11.2.16 Server-Side Request Forgery via downloadPdf

Quick assessment

Affected
UTMStack UTMStack
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 UTMStack 版本低于 11.2.16 中,存在一个服务端请求伪造(SSRF)漏洞。攻击者在经过身份认证后,可以通过向通过 GET /api/generate-pdf-report 接口暴露的 PdfService.downloadPdf() 方法提供一个未经验证的 URL 参数,从而诱导服务器请求任意内部资源。攻击者可利用此漏洞,迫使 web-pdf 微服务获取内部后端端点、OpenSearch 集群或云实例元数据服务中的敏感内部数据,并将这些数据渲染到返回的 PDF 文件中,从而导致敏感信息泄露。

CVSS 7.7 · High

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-82044

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
UTMStack < 11.2.16 Server-Side Request Forgery via downloadPdf
Source: CVE Program / CVE List V5
Vulnerability Description
UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticated attackers to make the server request arbitrary internal resources by supplying an unvalidated url parameter to the PdfService.downloadPdf() method exposed via GET /api/generate-pdf-report. Attackers can leverage this to force the web-pdf microservice to fetch internal backend endpoints, the OpenSearch cluster, or the cloud instance-metadata service, exposing sensitive internal data rendered into the returned PDF.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
UTMStack UTMStack 0 ~ 11.2.16 -

II. Public POCs for CVE-2026-82044

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-82044

请登录查看更多情报信息。

Other References for CVE-2026-82044 (3)

Same Patch Batch · UTMStack · 2026-10-02 · 7 CVEs total

CVE-2026-82041 9.9 CRITICAL UTMStack < 11.2.16 Missing Authorization via Command WebSocket
CVE-2026-82042 9.8 CRITICAL UTMStack < 11.2.16 Authentication Bypass via InternalApiKeyFilter
CVE-2026-82039 8.8 HIGH UTMStack < 11.2.16 SQL Injection via searchGroupsByFilter
CVE-2026-82045 6.5 MEDIUM UTMStack < 11.2.16 JPQL Injection via searchPropertyValues
CVE-2026-82043 5.3 MEDIUM UTMStack < 11.2.16 Account Enumeration via Password Reset Endpoint
CVE-2026-82040 5.0 MEDIUM UTMStack < 11.2.16 SSRF via IdentityProviderService

IV. Related Vulnerabilities

V. Comments for CVE-2026-82044

No comments yet


Leave a comment