Redpacketsecurity CVE-2026-82039: High-Risk SQL Injection in UTMStack
Article Content
- •CVE-2026-82039 is a high-risk SQL injection vulnerability in UTMStack.
- •Attackers can exploit this flaw to gain full database access with low-privilege accounts.
- •Immediate upgrade to version 11.2.16 is critical to mitigate the risk.
UTMStack versions before 11.2.16 contain a SQL injection vulnerability in the UtmAssetGroupService.searchQueryBuilder() method. This flaw allows authenticated attackers to inject arbitrary SQL through unsanitized inputs, enabling full database access and modification via the /api/utm-asset-groups/searchGroupsByFilter endpoint. The vulnerability has a CVSS score of 8.8, indicating high severity. Although active exploitation has not been confirmed, the risk is significant as low-privilege accounts could cause severe database impacts. Affected deployments include those accessible over the internet or partner networks. Administrators are advised to review access logs and database activity for unusual patterns. Immediate action is recommended to upgrade to the fixed version and restrict API access.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-1340 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions are affected?
Is this vulnerability being actively exploited?
What should I do to mitigate this issue?
Continue Reading
CVE-2026-88789: High-Risk XML Vulnerability in Apache Camel Quarkus CVE-2026-88789 is a vulnerability in the XSLT support extension of Apache Camel Quarkus, affecting versions from 3.2.0 to 3.40.0. This flaw allows attackers to read local files or access internal network locations by supplying a malicious XML document with external entity declarations. The vulnerability arises from…
SQL Injection Vulnerabilities Disclosed in WooCommerce and Captivate Sync Two SQL Injection vulnerabilities, CVE-2026-102379 and CVE-2026-62060, were disclosed on October 1, 2026. CVE-2026-102379 affects VillaTheme BuildKit for WooCommerce, allowing Blind SQL Injection, with a CVSS score of 8.5. CVE-2026-62060 impacts Captivate Sync, also permitting Blind SQL Injection, with a CVSS score of…