CVE-2026-82041

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied before forwarding supplied commands. Any authenticated user, regardless of role, can send arbitrary operating-system commands over gRPC to any connected agent, resulting in command execution on monitored endpoints where agent processes commonly run as root or SYSTEM.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-03: 110-03
Referenced assets1 URL
Full discourse1 post
  • ThreatAft@ThreatAft

    🔐 UTMStack Cluster — 7 CVEs, Peak CVSS 9.9 Missing Auth on STOMP Command WebSocket Seven vulnerabilities in UTMStack were disclosed on October 2, 2026. CVE-2026-82041 (CVSS 9.9) Fixed in 11.2.16. ROTATE INTERNAL_KEY. 🔗 https://threataft.com/articles/utmstack-cluster-cve-2026-82041-82042-82039-82044-82045-82043-82040?utm_source=twitter&utm_medium=social&utm_campaign=share #CyberSecurity #ThreatIntel

    0000033
    43 followersView on X

Explore more