{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/utmstack/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:utmstack:utmstack:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-82039"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["UTMStack (\u003c 11.2.16)"],"_cs_severities":["critical"],"_cs_tags":["sql-injection","vulnerability","web-application","remote-code-execution","cve-2026-82041","ssrf","internal-reconnaissance"],"_cs_type":"advisory","_cs_vendors":["UTMStack"],"content_html":"\u003cp\u003eUTMStack versions prior to 11.2.16 contain a critical SQL injection vulnerability located within the UtmAssetGroupService.searchQueryBuilder() method. This vulnerability arises due to the unsanitized concatenation of user-supplied input into native PostgreSQL queries via String.format(). Specifically, an authenticated attacker can target the GET /api/utm-asset-groups/searchGroupsByFilter endpoint, passing malicious payloads through the assetType and groupName parameters. Because the application interacts with the backend database using DBA-level privileges, successful exploitation grants the attacker full access to the database, including the ability to read, modify, or delete sensitive data, and potentially escalate to filesystem access on the hosting server.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an authenticated attacker to compromise the integrity and confidentiality of the UTMStack database. Given the elevated DBA privileges of the application, this vulnerability provides a vector for complete data exfiltration, unauthorized administrative actions, and potential remote code execution via database-linked filesystem commands.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpgrade all instances of UTMStack to version 11.2.16 or later immediately. Access logs should be audited for anomalous activity targeting the /api/utm-asset-groups/searchGroupsByFilter endpoint, particularly requests containing SQL control characters or keywords (e.g., UNION, SELECT, OR, 1=1) within the assetType or groupName parameters.\u003c/p\u003e\n","date_modified":"2026-10-02T22:27:31Z","date_published":"2026-10-02T20:27:13Z","id":"https://feed.craftedsignal.io/briefs/2026-10-utmstack-sqli/","summary":"UTMStack versions prior to 11.2.16 are vulnerable to an authenticated SQL injection in the UtmAssetGroupService, allowing attackers to execute arbitrary commands with DBA privileges.","title":"SQL Injection in UTMStack via UtmAssetGroupService","url":"https://feed.craftedsignal.io/briefs/2026-10-utmstack-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - UTMStack","version":"https://jsonfeed.org/version/1.1"}