UTMStack Cluster — 7 CVEs, Peak CVSS 9.9 Missing Auth on STOMP Command WebSocket
A single authenticated user with any role can execute arbitrary OS commands on every monitored endpoint in your UTMStack deployment. Seven CVEs dropped for the open-source SIEM platform, all fixed in 11.2.16. The cluste
A single authenticated user with any role can execute arbitrary OS commands on every monitored endpoint in your UTMStack deployment. Seven CVEs dropped for the open-source SIEM platform, all fixed in 11.2.16.
The cluster:
CVE-2026-82041 (CVSS 9.9) — no role check on /command/{hostname} STOMP websocket → RCE on monitored endpoints
CVE-2026-82042 (CVSS 9.8) — Utm-Internal-Key header bypasses all auth, grants full admin API access
CVE-2026-82039 (CVSS 8.8) — SQL injection in asset group search via String.format() without parameter binding
CVE-2026-82044 (CVSS 7.7) — SSRF in PDF generation, can reach OpenSearch cluster and cloud metadata
CVE-2026-82045 (CVSS 6.5) — JPQL injection exposes credential tables including jhi_user
CVE-2026-82043 (CVSS 5.3) — account enumeration via password reset response discrepancy
CVE-2026-82040 (CVSS 5.0) — SSRF in identity provider metadata URL validation
Single fix: upgrade to UTMStack 11.2.16. Rotate INTERNAL_KEY. Audit agent command logs.
Full technical breakdown on ThreatAft →
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.