Skip to content
CVE-2026-82039: High-Risk SQL Injection in UTMStack

CVE-2026-82039: High-Risk SQL Injection in UTMStack

First seen 4 Oct 2026, 04:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 06:06 UTC
  • •CVE-2026-82039 is a high-risk SQL injection vulnerability in UTMStack.
  • •Attackers can exploit this flaw to gain full database access with low-privilege accounts.
  • •Immediate upgrade to version 11.2.16 is critical to mitigate the risk.

UTMStack versions before 11.2.16 contain a SQL injection vulnerability in the UtmAssetGroupService.searchQueryBuilder() method. This flaw allows authenticated attackers to inject arbitrary SQL through unsanitized inputs, enabling full database access and modification via the /api/utm-asset-groups/searchGroupsByFilter endpoint. The vulnerability has a CVSS score of 8.8, indicating high severity. Although active exploitation has not been confirmed, the risk is significant as low-privilege accounts could cause severe database impacts. Affected deployments include those accessible over the internet or partner networks. Administrators are advised to review access logs and database activity for unusual patterns. Immediate action is recommended to upgrade to the fixed version and restrict API access.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-01-29
CVE-2026-1340 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-02
CVE-2026-82039 published
CVE-2026-82039 was disclosed, detailing a SQL injection vulnerability in UTMStack affecting versions before 11.2.16.
Ismalicious
2026-10-03
CVE-2026-82039 alert issued
Redpacketsecurity issued an alert regarding the SQL injection vulnerability, emphasizing the need for urgent patching.
Redpacketsecurity

More articles in this cluster (3)

Following this threat?

Track CVE-2026-1340 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions are affected?
UTMStack versions prior to 11.2.16 are affected by this vulnerability.
Is this vulnerability being actively exploited?
Active exploitation has not been confirmed, but the risk remains high.
What should I do to mitigate this issue?
Upgrade to UTMStack version 11.2.16 immediately and restrict API access until patched.