CVE-2026-82041EPSS p35.9%
CVE-2026-82041CVE-2026-82041
Description
UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied before forwarding supplied commands. Any authenticated user, regardless of role, can send arbitrary operating-system commands over gRPC to any connected agent, resulting in command execution on monitored endpoints where agent processes commonly run as root or SYSTEM.
Scoring
| CVSS | 9.9 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 0.44% probability of exploitation · percentile 35.9% · 2026-10-05T12:00:23Z |
| Last modified | 2026-10-05 |