Skip to content
Threat Feed
critical advisory

SQL Injection in UTMStack via UtmAssetGroupService

UTMStack versions prior to 11.2.16 are vulnerable to an authenticated SQL injection in the UtmAssetGroupService, allowing attackers to execute arbitrary commands with DBA privileges.

CVE search metadata

CVE search record: CVE-2026-82039. Severity: high. CVSS: 8.8. KEV: no. Product: UTMStack (< 11.2.16). Brief: SQL Injection in UTMStack via UtmAssetGroupService. Brief link: https://feed.craftedsignal.io/briefs/2026-10-utmstack-sqli/

What's new

  • 1. added detection rule: Detect CVE-2026-82044 Exploitation - SSRF via PdfService Oct 2, 22:27 via nvd
  • 2. added detection rule: Detect Unauthorized Access via Utm-Internal-Key Oct 2, 22:27 via nvd
  • 3. added coverage for UTMStack (< 11.2.16) Oct 2, 22:27 via nvd

UTMStack versions prior to 11.2.16 contain a critical SQL injection vulnerability located within the UtmAssetGroupService.searchQueryBuilder() method. This vulnerability arises due to the unsanitized concatenation of user-supplied input into native PostgreSQL queries via String.format(). Specifically, an authenticated attacker can target the GET /api/utm-asset-groups/searchGroupsByFilter endpoint, passing malicious payloads through the assetType and groupName parameters. Because the application interacts with the backend database using DBA-level privileges, successful exploitation grants the attacker full access to the database, including the ability to read, modify, or delete sensitive data, and potentially escalate to filesystem access on the hosting server.

Impact

Successful exploitation of this vulnerability allows an authenticated attacker to compromise the integrity and confidentiality of the UTMStack database. Given the elevated DBA privileges of the application, this vulnerability provides a vector for complete data exfiltration, unauthorized administrative actions, and potential remote code execution via database-linked filesystem commands.

Recommendation

Upgrade all instances of UTMStack to version 11.2.16 or later immediately. Access logs should be audited for anomalous activity targeting the /api/utm-asset-groups/searchGroupsByFilter endpoint, particularly requests containing SQL control characters or keywords (e.g., UNION, SELECT, OR, 1=1) within the assetType or groupName parameters.


Immediate actions

Upgrade UTMStack to version 11.2.16 or later

IT Operations 24h

Threat Hunt

Audit web access logs for GET requests to /api/utm-asset-groups/searchGroupsByFilter containing SQL syntax

T1190 high high confidence hunt now

Data: Web server access logs

Mitigations

Upgrade to 11.2.16

immediate IT Operations

CVE-2026-82039

Detection coverage 2

Detect Unauthorized Access via Utm-Internal-Key

high

Detects potential exploitation of CVE-2026-82042 by monitoring for the presence of the 'Utm-Internal-Key' header in HTTP requests, which should generally not be present in legitimate client-facing traffic.

sigma tactics: initial_access techniques: T1199 sources: webserver

Detect CVE-2026-82044 Exploitation - SSRF via PdfService

high

Detects exploitation attempts against the /api/generate-pdf-report endpoint where the URL parameter attempts to access internal infrastructure.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →