CVE-2026-82041 is a critical missing authorization flaw in UTMStack before 11.2.16 that lets any authenticated user, whatever their role, send arbitrary operating-system commands to connected agents.
What Is It
CVE-2026-82041 is a missing authorization vulnerability (CWE-862) in UTMStack. It sits in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination. The handler forwards the commands it receives without any role check or command allowlist.
Any authenticated user can therefore send arbitrary OS commands over gRPC to any connected agent, and those commands run on the monitored endpoints. VulnCheck disclosed the issue, and it was published to NVD on October 2, 2026, with a status of "Received."
Why It Matters
- Severity: CVSS 3.1 base score 9.9 (CRITICAL), vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. - Low barrier: The attack works over the network with low complexity. It needs only low privileges and no user interaction.
- Changed scope: A foothold in the UTMStack platform turns into command execution on the endpoints it monitors. According to the advisory, agent processes on those endpoints commonly run as root or SYSTEM.
- CVSS 4.0: VulnCheck's secondary CVSS 4.0 score is 6.5 (MEDIUM). That vector shows no impact on the vulnerable component itself, but High confidentiality, integrity, and availability impact on subsequent systems, meaning the downstream endpoints.
In practice, a single low-privileged UTMStack account could be enough to compromise every endpoint with a connected agent.
Exploitation status: CISA KEV contains no entry for this CVE, and the supplied data does not confirm active exploitation.
What's Vulnerable
- Vendor/Product: UTMStack / UTMStack
- Affected versions: All versions before 11.2.16 (semver, from 0 up to but not including 11.2.16)
- Repository: https://github.com/utmstack/UTMStack
Patch Status
The fix is in UTMStack 11.2.16. The supplied references include the v11.2.16 release and the commit that fixes the issue (4e7a727c3b8d8e2ad020d3b4f982a6d085dbecdd). Organizations running UTMStack should upgrade to 11.2.16 or later. CISA has not issued a KEV required action or due date for this CVE.