SQL Injection in UTMStack via UtmAssetGroupService
UTMStack versions prior to 11.2.16 are vulnerable to an authenticated SQL injection in the UtmAssetGroupService, allowing attackers to execute arbitrary commands with DBA privileges.
CVE search metadata
CVE search record: CVE-2026-82039. Severity: high. CVSS: 8.8. KEV: no. Product: UTMStack (< 11.2.16). Brief: SQL Injection in UTMStack via UtmAssetGroupService. Brief link: https://feed.craftedsignal.io/briefs/2026-10-utmstack-sqli/
What's new
UTMStack versions prior to 11.2.16 contain a critical SQL injection vulnerability located within the UtmAssetGroupService.searchQueryBuilder() method. This vulnerability arises due to the unsanitized concatenation of user-supplied input into native PostgreSQL queries via String.format(). Specifically, an authenticated attacker can target the GET /api/utm-asset-groups/searchGroupsByFilter endpoint, passing malicious payloads through the assetType and groupName parameters. Because the application interacts with the backend database using DBA-level privileges, successful exploitation grants the attacker full access to the database, including the ability to read, modify, or delete sensitive data, and potentially escalate to filesystem access on the hosting server.
Impact
Successful exploitation of this vulnerability allows an authenticated attacker to compromise the integrity and confidentiality of the UTMStack database. Given the elevated DBA privileges of the application, this vulnerability provides a vector for complete data exfiltration, unauthorized administrative actions, and potential remote code execution via database-linked filesystem commands.
Recommendation
Upgrade all instances of UTMStack to version 11.2.16 or later immediately. Access logs should be audited for anomalous activity targeting the /api/utm-asset-groups/searchGroupsByFilter endpoint, particularly requests containing SQL control characters or keywords (e.g., UNION, SELECT, OR, 1=1) within the assetType or groupName parameters.
Immediate actions
Upgrade UTMStack to version 11.2.16 or later
Threat Hunt
Audit web access logs for GET requests to /api/utm-asset-groups/searchGroupsByFilter containing SQL syntax
Data: Web server access logs
Mitigations
Upgrade to 11.2.16
CVE-2026-82039
Detection coverage 2
Detect Unauthorized Access via Utm-Internal-Key
highDetects potential exploitation of CVE-2026-82042 by monitoring for the presence of the 'Utm-Internal-Key' header in HTTP requests, which should generally not be present in legitimate client-facing traffic.
Detect CVE-2026-82044 Exploitation - SSRF via PdfService
highDetects exploitation attempts against the /api/generate-pdf-report endpoint where the URL parameter attempts to access internal infrastructure.
Detection queries are available on the platform. Get full rules →