UTMStack before version 11.2.16 contains a critical authentication bypass (CVSS 3.1: 9.8). Anyone holding the internal API key can get full administrative API access without a user account or JWT.
What Is It
CVE-2026-82042 is a missing-authentication flaw (CWE-306) in UTMStack's InternalApiKeyFilter. The filter accepts any request that carries a Utm-Internal-Key header matching the value of the INTERNAL_KEY environment variable. According to the NVD description, the filter grants this access with:
- No path restriction (it works on any endpoint)
- No constant-time comparison
- No rate limiting
- No audit logging
A remote attacker who obtains the key value can authenticate as an administrator without a user account or JWT.
Why It Matters
The flaw is rated CRITICAL: CVSS 3.1 base score 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and CVSS 4.0 score 9.3 from VulnCheck. It is reachable over the network with low attack complexity, and it needs no privileges or user interaction.
With a valid key, an attacker can:
- Create accounts
- Manage users
- Exfiltrate data
- Modify security rules
UTMStack is a security monitoring platform, so changing its security rules could weaken an organization's defensive visibility.
None of the sources cited below report active exploitation of this vulnerability.
What's Vulnerable
- Vendor: UTMStack
- Product: UTMStack
- Affected versions: all versions before 11.2.16 (semver range
0to<11.2.16) - Repository: github.com/utmstack/UTMStack
The NVD record lists no CPE entries yet. Its status is "Received" and it was published on 2026-10-02.
Patch Status
The issue is fixed in UTMStack 11.2.16. The release tag and the fix commit (4e7a727c) are both published on GitHub. Administrators should upgrade to 11.2.16 or later. Because the bypass depends on the INTERNAL_KEY value, also treat any deployment where that key may have been exposed as a priority.