Cyber & AI intelligence
Wasteland.
Briefs indexed2982
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-82041 2026-10-02

UTMStack Missing Authorization Flaw Lets Any Authenticated User Run OS Commands on Monitored Endpoints (CVE-2026-82041)

"CVE-2026-82041 is a critical missing authorization flaw in UTMStack before 11.2.16 that lets any authenticated user, whatever their role, send arbitrary operating-system commands to connected agents."

CVE-2026-82041 is a critical missing authorization flaw in UTMStack before 11.2.16 that lets any authenticated user, whatever their role, send arbitrary operating-system commands to connected agents.

What Is It

CVE-2026-82041 is a missing authorization vulnerability (CWE-862) in UTMStack. It sits in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination. The handler forwards the commands it receives without any role check or command allowlist.

Any authenticated user can therefore send arbitrary OS commands over gRPC to any connected agent, and those commands run on the monitored endpoints. VulnCheck disclosed the issue, and it was published to NVD on October 2, 2026, with a status of "Received."

Why It Matters

In practice, a single low-privileged UTMStack account could be enough to compromise every endpoint with a connected agent.

Exploitation status: CISA KEV contains no entry for this CVE, and the supplied data does not confirm active exploitation.

What's Vulnerable

Patch Status

The fix is in UTMStack 11.2.16. The supplied references include the v11.2.16 release and the commit that fixes the issue (4e7a727c3b8d8e2ad020d3b4f982a6d085dbecdd). Organizations running UTMStack should upgrade to 11.2.16 or later. CISA has not issued a KEV required action or due date for this CVE.

Sources