GHSA-phx4-fx7q-vfw9CriticalCVSS 9.8
UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote...
🔗 CVE IDs covered (1)
📋 Description
UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable value, which the InternalApiKeyFilter accepts for any endpoint without path restriction, constant-time comparison, rate limiting, or audit logging. Attackers who obtain the key value can authenticate without a user account or JWT to create accounts, manage users, exfiltrate data, and modify security rules.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2026-82042
- https://github.com/utmstack/UTMStack/commit/4e7a727c3b8d8e2ad020d3b4f982a6d085dbecdd
- https://github.com/UTMStack/UTMStack/releases/tag/v11.2.16
- https://www.vulncheck.com/advisories/utmstack-authentication-bypass-via-internalapikeyfilter
- https://github.com/advisories/GHSA-phx4-fx7q-vfw9