CVE-2026-82043: UTMStack < 11.2.16 Account Enumeration via Password Reset Endpoint
UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated attackers to determine registered email addresses by observing differing HTTP responses from the POST /api/account/reset-password/init endpoint. Attackers can submit arbitrary email addresses and distinguish registered accounts, which return 200 OK, from unregistered accounts, which trigger a 500 Internal Server Error with backend error details, enabling targeted phishing or credential attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
UTMStackto a version that resolves this vulnerability.Fixed in 11.2.16
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated remote attacker who can reach the POST /api/account/reset-password/init endpoint can submit email addresses and compare the HTTP responses.
What response behavior indicates that an email address is registered?
A registered account email receives a 200 OK response. An unregistered email produces a 500 Internal Server Error that exposes backend error details.
Are default or unauthenticated deployments affected?
The affected password-reset endpoint can be queried without authentication, so deployments exposing it to remote users are susceptible. The provided information does not state whether the endpoint is enabled in a default installation.
What version addresses the issue?
UTMStack 11.2.16 is the referenced fixed release. Versions before 11.2.16 are affected.