OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-82039

HIGH · CVSS 8.8 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

UTMStack versions prior to 11.2.16 are vulnerable to a SQL injection flaw in the UtmAssetGroupService.searchQueryBuilder() method, allowing authenticated attackers to inject malicious SQL through unsanitized input parameters. This vulnerability can be exploited via the GET /api/utm-asset-groups/searchGroupsByFilter endpoint, granting attackers the ability to execute arbitrary SQL commands with DBA privileges, leading to full database access and potential filesystem manipulation. Organizations using affected versions should prioritize patching this vulnerability to mitigate the risk of data breaches and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82039
Severity
HIGH
CVSS
8.8
EPSS
0.34%

Original NVD Description

UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType and groupName values that are inserted unsanitized into a native PostgreSQL query via String.format(). Attackers can exploit the GET /api/utm-asset-groups/searchGroupsByFilter endpoint to execute arbitrary SQL with DBA privileges, enabling full database read, data modification, and potential filesystem access.