chiprook
← Security
SecurityOctober 3, 2026, 09:42

UTMStack Cluster hit by 7 CVEs, peak CVSS 9.9 missing auth on STOMP WebSocket

Seven CVEs were disclosed in the open-source SIEM platform UTMStack, including a missing role check on the /command/{hostname} STOMP websocket (CVSS 9.9) that lets any authenticated user run OS commands on every monitored endpoint. All flaws are fixed in version 11.2.16.

UTMStack Cluster hit by 7 CVEs, peak CVSS 9.9 missing auth on STOMP WebSocket
#UTMStack
Read next
Security

TASK#STOMP Windows backdoor steals documents, Wi-Fi passwords and screenshots

Security

CVE-2026-92948: vm2 sandbox escape via node:test rated 9.9

Security

GitLab EE CVE-2026-87719: critical 9.9 flaw leaks search credentials

Security

LXD hit by three critical flaws rated up to 9.9