UTMStack Cluster — 7 CVEs, Peak CVSS 9.9 Missing Auth on STOMP Command WebSocket
A single authenticated user with any role can execute arbitrary OS commands on every monitored endpoint in your UTMStack deployment. Seven CVEs dropped for the open-source SIEM platform, all fixed in 11.2.16. The cluster: CVE-2026-82041 (CVSS 9.9) — no role check on /command/{hostname} STOMP websocket → RCE on monitored endpoints CVE-2026-82042 (CVSS 9.8) — Utm-Internal-Key header bypasses all…
The UTMStack open-source SIEM platform has been hit by seven critical vulnerabilities (CVEs) with the highest severity reaching 9.9. The fixes are all incorporated in version 11.2.16.
First and foremost, an authenticated user can execute arbitrary OS commands on every monitored endpoint due to missing authorization on the /command/{hostname} STOMP websocket. This vulnerability (CVE-2026-82041) carries the top CVSS score of 9.9, indicating extreme severity.
Another high severity issue (CVE-2026-82042) stems from bypassing all authentication through the Utm-Internal-Key header. This allows a user to gain full admin API access across the board.
SQL injection vulnerabilities (CVE-2026-82039) exist in the asset group search functionality due to improper String.format() parameters. The SSRF flaw in PDF generation (CVE-2026-82044) enables attackers to reach the OpenSearch cluster and cloud metadata.
Two more vulnerabilities (CVE-2026-82045 and CVE-2026-82043) relate to JPQL injection, exposing credential tables and enabling account enumeration through password reset responses. Lastly, a relatively lower severity issue (CVE-2026-82040) involves SSRF in identity provider metadata URL validation.
The straightforward resolution path is to upgrade to version 11.2.16. Additionally, rotating the INTERNAL_KEY and auditing agent command logs are recommended steps to mitigate the risks posed by these vulnerabilities.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.