OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-82041

CRITICAL · CVSS 9.9 EPSS 0.44% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

UTMStack versions prior to 11.2.16 are vulnerable due to a missing authorization check in the command processing function, allowing any authenticated user to execute arbitrary operating-system commands on connected agents. This critical flaw can lead to unauthorized command execution on endpoints, which typically operate with elevated privileges such as root or SYSTEM. Organizations using UTMStack should prioritize patching this vulnerability to mitigate the risk of potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82041
Severity
CRITICAL
CVSS
9.9
EPSS
0.44%

Original NVD Description

UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied before forwarding supplied commands. Any authenticated user, regardless of role, can send arbitrary operating-system commands over gRPC to any connected agent, resulting in command execution on monitored endpoints where agent processes commonly run as root or SYSTEM.