Cyber & AI intelligence
Wasteland.
Briefs indexed2982
Issues30
Published Mondays07:30 CT
CVE · Critical CVE-2026-82042 2026-10-02

UTMStack Authentication Bypass via Internal API Key (CVE-2026-82042)

"UTMStack before version 11.2.16 contains a critical authentication bypass (CVSS 3.1: 9.8). Anyone holding the internal API key can get full administrative API access without a user account or JWT."

UTMStack before version 11.2.16 contains a critical authentication bypass (CVSS 3.1: 9.8). Anyone holding the internal API key can get full administrative API access without a user account or JWT.

What Is It

CVE-2026-82042 is a missing-authentication flaw (CWE-306) in UTMStack's InternalApiKeyFilter. The filter accepts any request that carries a Utm-Internal-Key header matching the value of the INTERNAL_KEY environment variable. According to the NVD description, the filter grants this access with:

A remote attacker who obtains the key value can authenticate as an administrator without a user account or JWT.

Why It Matters

The flaw is rated CRITICAL: CVSS 3.1 base score 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and CVSS 4.0 score 9.3 from VulnCheck. It is reachable over the network with low attack complexity, and it needs no privileges or user interaction.

With a valid key, an attacker can:

UTMStack is a security monitoring platform, so changing its security rules could weaken an organization's defensive visibility.

None of the sources cited below report active exploitation of this vulnerability.

What's Vulnerable

The NVD record lists no CPE entries yet. Its status is "Received" and it was published on 2026-10-02.

Patch Status

The issue is fixed in UTMStack 11.2.16. The release tag and the fix commit (4e7a727c) are both published on GitHub. Administrators should upgrade to 11.2.16 or later. Because the bypass depends on the INTERNAL_KEY value, also treat any deployment where that key may have been exposed as a priority.

Sources