CVE-2026-82043: UTMStack < 11.2.16 Account Enumeration via Password Reset Endpoint

Published Oct 2, 2026
·
Updated

UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated attackers to determine registered email addresses by observing differing HTTP responses from the POST /api/account/reset-password/init endpoint. Attackers can submit arbitrary email addresses and distinguish registered accounts, which return 200 OK, from unregistered accounts, which trigger a 500 Internal Server Error with backend error details, enabling targeted phishing or credential attacks.

Affected Software

1 affected component
UTMStack UTMStack<11.2.16

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade UTMStack to a version that resolves this vulnerability.

    Fixed in 11.2.16

Event History

Oct 2, 2026
CVE Published
via MITRE·08:17 PM
Data Sourced
via MITRE·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any unauthenticated remote attacker who can reach the POST /api/account/reset-password/init endpoint can submit email addresses and compare the HTTP responses.

2

What response behavior indicates that an email address is registered?

A registered account email receives a 200 OK response. An unregistered email produces a 500 Internal Server Error that exposes backend error details.

3

Are default or unauthenticated deployments affected?

The affected password-reset endpoint can be queried without authentication, so deployments exposing it to remote users are susceptible. The provided information does not state whether the endpoint is enabled in a default installation.

4

What version addresses the issue?

UTMStack 11.2.16 is the referenced fixed release. Versions before 11.2.16 are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203