UTMStack Cluster hit by 7 CVEs, peak CVSS 9.9 missing auth on STOMP WebSocket
Seven CVEs were disclosed in the open-source SIEM platform UTMStack, including a missing role check on the /command/{hostname} STOMP websocket (CVSS 9.9) that lets any authenticated user run OS commands on every monitored endpoint. All flaws are fixed in version 11.2.16.
- CVE-2026-82041 (9.9): no role check on /command/{hostname} STOMP websocket leads to RCE
- CVE-2026-82042 (9.8): Utm-Internal-Key header bypasses auth and grants full admin API access
- CVE-2026-82039 (8.8): SQL injection in asset group search via String.format()
- Single fix: upgrade to UTMStack 11.2.16 and rotate INTERNAL_KEY
Read next
Security