UTMStack
7 known vulnerabilities in UTMStack, 1 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-82045 CVSS 7.1 high UTMStack before 11.2.16 contains a JPQL injection vulnerability that allows authenticated attackers to read arbitrary entity data by…
- CVE-2026-82044 CVSS 6.3 medium UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticated attackers to make the server…
- CVE-2026-82043 CVSS 6.9 medium UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated attackers to determine registered email…
- CVE-2026-82042 CVSS 9.3 critical UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API…
- CVE-2026-82041 CVSS 6.5 medium UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped…
- CVE-2026-82040 CVSS 5.3 medium UTMStack before 11.2.16 contains a server-side request forgery vulnerability in IdentityProviderService.validateMetadataUrl() that allows…
- CVE-2026-82039 CVSS 8.7 high UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated…