CVE-2026-82040: UTMStack < 11.2.16 SSRF via IdentityProviderService
UTMStack before 11.2.16 contains a server-side request forgery vulnerability in IdentityProviderService.validateMetadataUrl() that allows authenticated attackers to make the server send requests to arbitrary internal or cloud metadata hosts by supplying a malicious metadata URL to the identity-providers endpoint. Attackers can exploit the POST/PUT /api/identity-providers endpoint with no validation of target host, IP, or scheme to perform internal network port scanning and access cloud instance-metadata services.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs authenticated access with the ability to submit POST or PUT requests to /api/identity-providers. No user interaction is required.
What systems can the vulnerable server be induced to contact?
The metadata URL is not validated for target host, IP address, or scheme. An attacker can direct requests to arbitrary internal hosts or cloud instance-metadata services, including for internal port scanning.
Are installations before version 11.2.16 affected?
UTMStack versions before 11.2.16 are affected. Version 11.2.16 is identified in the provided release reference as the fixed version.