CVE-2026-82039
published 2026-10-02CVE-2026-82039: UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject…
PriorityP263high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.34%
25.1th percentile
UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType and groupName values that are inserted unsanitized into a native PostgreSQL query via String.format(). Attackers can exploit the GET /api/utm-asset-groups/searchGroupsByFilter endpoint to execute arbitrary SQL with DBA privileges, enabling full database read, data modification, and potential filesystem access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| utmstack | utmstack | < 11.2.16 | 11.2.16 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
UTMStack prior 11.2.16 UtmAssetGroupService searchGroupsByFilter UtmAssetGroupService.searchQueryBuilder assetType/groupName sql injection
vuldb·2026-10-02·CVSS 8.8
CVE-2026-82039 [HIGH] UTMStack prior 11.2.16 UtmAssetGroupService searchGroupsByFilter UtmAssetGroupService.searchQueryBuilder assetType/groupName sql injection
A vulnerability was found in UTMStack. It has been declared as critical. Affected by this issue is the function UtmAssetGroupService.searchQueryBuilder of the file /api/utm-asset-groups/searchGroupsByFilter of the component UtmAssetGroupService. Such manipulation of the argument assetType/groupName leads to sql injection.
This vulnerability is documented as CVE-2026-82039. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
GHSA
UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType
ghsa_unreviewed·2026-10-02
CVE-2026-82039 [HIGH] CWE-89 UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType
UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType and groupName values that are inserted unsanitized into a native PostgreSQL query via String.format(). Attackers can exploit the GET /api/utm-asset-groups/searchGroupsByFilter endpoint to execute arbitrary SQL with DBA privileges, enabling full database read, data modification, and potential filesystem access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-10-02
Published