DEV Community

threataft
threataft

Posted on Originally published at threataft.com

UTMStack Cluster — 7 CVEs, Peak CVSS 9.9 Missing Auth on STOMP Command WebSocket

A single authenticated user with any role can execute arbitrary OS commands on every monitored endpoint in your UTMStack deployment. Seven CVEs dropped for the open-source SIEM platform, all fixed in 11.2.16.

The cluster:

CVE-2026-82041 (CVSS 9.9) — no role check on /command/{hostname} STOMP websocket → RCE on monitored endpoints
CVE-2026-82042 (CVSS 9.8) — Utm-Internal-Key header bypasses all auth, grants full admin API access
CVE-2026-82039 (CVSS 8.8) — SQL injection in asset group search via String.format() without parameter binding
CVE-2026-82044 (CVSS 7.7) — SSRF in PDF generation, can reach OpenSearch cluster and cloud metadata
CVE-2026-82045 (CVSS 6.5) — JPQL injection exposes credential tables including jhi_user
CVE-2026-82043 (CVSS 5.3) — account enumeration via password reset response discrepancy
CVE-2026-82040 (CVSS 5.0) — SSRF in identity provider metadata URL validation

Single fix: upgrade to UTMStack 11.2.16. Rotate INTERNAL_KEY. Audit agent command logs.

Full technical breakdown on ThreatAft →

Top comments (0)