Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-82045— UTMStack < 11.2.16 JPQL Injection via searchPropertyValues

Quick assessment

Affected
UTMStack UTMStack
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

UTMStack 11.2.16 之前的版本存在一个 JPQL 注入漏洞,攻击者可以通过利用 方法,以认证用户身份读取任意实体数据。该方法使用 构建 JPQL 查询,并通过 执行查询,且未使用参数绑定以防止注入。攻击者可以在 GET 请求端点 的 value 参数中注入恶意的 JPQL 代码,从而提取敏感数据,包括如 这样的凭据表。

CVSS 6.5 · Medium EPSS 0.26% · P16

Affected Version Matrix 1

VendorProduct Version RangeStatus
UTMStack UTMStack < 11.2.16 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-82045

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
UTMStack < 11.2.16 JPQL Injection via searchPropertyValues
Source: CVE Program / CVE List V5
Vulnerability Description
UTMStack before 11.2.16 contains a JPQL injection vulnerability that allows authenticated attackers to read arbitrary entity data by exploiting UtmNetworkScanService.searchPropertyValues(), which builds a JPQL query with String.format() and executes it via em.createQuery() without parameter binding. Attackers can inject malicious JPQL through the value parameter in the GET /api/utm-network-scans/searchPropertyValues endpoint to extract sensitive data including credential tables such as jhi_user.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
UTMStack UTMStack 0 ~ 11.2.16 -

II. Public POCs for CVE-2026-82045

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-82045

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-82045 (1)

Vendor Pages for CVE-2026-82045 (1)

Same Patch Batch · UTMStack · 2026-10-02 · 7 CVEs total

CVE-2026-82041 9.9 CRITICAL UTMStack < 11.2.16 Missing Authorization via Command WebSocket
CVE-2026-82042 9.8 CRITICAL UTMStack < 11.2.16 Authentication Bypass via InternalApiKeyFilter
CVE-2026-82039 8.8 HIGH UTMStack < 11.2.16 SQL Injection via searchGroupsByFilter
CVE-2026-82044 7.7 HIGH UTMStack < 11.2.16 Server-Side Request Forgery via downloadPdf
CVE-2026-82043 5.3 MEDIUM UTMStack < 11.2.16 Account Enumeration via Password Reset Endpoint
CVE-2026-82040 5.0 MEDIUM UTMStack < 11.2.16 SSRF via IdentityProviderService

IV. Related Vulnerabilities

V. Comments for CVE-2026-82045

No comments yet


Leave a comment