{
  "id": 11583942,
  "title": "UTMStack Cluster — 7 CVEs, Peak CVSS 9.9 Missing Auth on STOMP Command WebSocket",
  "url": "https://urgent.news/2026/10/03/utmstack-cluster-7-cves-peak-cvss-9-9-missing-auth-on-stomp-command",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-03T02:42:13.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/threataft_dev/utmstack-cluster-7-cves-peak-cvss-99-missing-auth-on-stomp-command-websocket-27b8"
  },
  "original_language": "en",
  "account": "The UTMStack open-source SIEM platform has been hit by seven critical vulnerabilities (CVEs) with the highest severity reaching 9.9. The fixes are all incorporated in version 11.2.16.\n\nFirst and foremost, an authenticated user can execute arbitrary OS commands on every monitored endpoint due to missing authorization on the /command/{hostname} STOMP websocket. This vulnerability (CVE-2026-82041) carries the top CVSS score of 9.9, indicating extreme severity.\n\nAnother high severity issue (CVE-2026-82042) stems from bypassing all authentication through the Utm-Internal-Key header. This allows a user to gain full admin API access across the board.\n\nSQL injection vulnerabilities (CVE-2026-82039) exist in the asset group search functionality due to improper String.format() parameters. The SSRF flaw in PDF generation (CVE-2026-82044) enables attackers to reach the OpenSearch cluster and cloud metadata.\n\nTwo more vulnerabilities (CVE-2026-82045 and CVE-2026-82043) relate to JPQL injection, exposing credential tables and enabling account enumeration through password reset responses. Lastly, a relatively lower severity issue (CVE-2026-82040) involves SSRF in identity provider metadata URL validation.\n\nThe straightforward resolution path is to upgrade to version 11.2.16. Additionally, rotating the INTERNAL_KEY and auditing agent command logs are recommended steps to mitigate the risks posed by these vulnerabilities.",
  "summary": "A single authenticated user with any role can execute arbitrary OS commands on every monitored endpoint in your UTMStack deployment. Seven CVEs dropped for the open-source SIEM platform, all fixed in 11.2.16. The cluster: CVE-2026-82041 (CVSS 9.9) — no role check on /command/{hostname} STOMP websocket → RCE on monitored endpoints CVE-2026-82042 (CVSS 9.8) — Utm-Internal-Key header bypasses all…",
  "key_points": [
    "Seven critical CVEs discovered in UTMStack platform",
    "Highest severity CVE-2026-82041 with CVSS 9.9",
    "Upgrade to version 11.2.16 recommended"
  ],
  "editors_take": "The UTMStack vulnerabilities give attackers wide-ranging control, from arbitrary OS commands to admin API access and data exposure, which users can mitigate by upgrading to version 11.2.16 and taking additional precautions.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}