Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/utmstack/UTMStack

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

UTMStack versions prior to 11.2.16 have an account enumeration vulnerability. This flaw allows unauthenticated attackers to determine if an email address is registered by submitting it to the password reset initiation endpoint. Registered emails return a 200 OK response, while unregistered ones cause a 500 Internal Server Error with backend details. This behavior enables attackers to distinguish valid accounts, potentially facilitating targeted phishing or credential attacks.

Join the discussion

UTMStack versions prior to 11.2.16 have a JPQL injection vulnerability in the UtmNetworkScanService.searchPropertyValues() method. Authenticated attackers can exploit this flaw by injecting malicious JPQL through the value parameter in the GET /api/utm-network-scans/searchPropertyValues endpoint. This allows unauthorized reading of arbitrary entity data, including sensitive credential tables such as jhi_user.

Join the discussion

UTMStack versions prior to 11.2.16 contain a server-side request forgery (SSRF) vulnerability. Authenticated attackers can exploit this flaw by supplying an unvalidated URL parameter to the PdfService.downloadPdf() method via the GET /api/generate-pdf-report endpoint. This allows the attacker to make the server request arbitrary internal resources, potentially exposing sensitive internal data rendered into the generated PDF report.

Join the discussion

UTMStack versions before 11.2.16 have an authentication bypass vulnerability (CVE-2026-82042) that allows remote attackers to gain full administrative API access by using a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable. This bypass does not require a user account or JWT and lacks path restrictions, constant-time comparison, rate limiting, or audit logging. Exploitation enables attackers to create accounts, manage users, exfiltrate data, and modify security rules.

Join the discussion

UTMStack versions before 11.2.16 have a missing authorization vulnerability in the UTMIncidentCommandWebsocket.processCommand() handler. This handler, mapped to the /command/{hostname} STOMP destination, does not enforce role checks or command allowlists before forwarding commands. As a result, any authenticated user can execute arbitrary operating-system commands on monitored endpoints where agents typically run with high privileges.

Join the discussion

UTMStack versions before 11.2.16 have a SQL injection vulnerability in the UtmAssetGroupService.searchQueryBuilder() method. Authenticated attackers can exploit this flaw by sending crafted requests to the GET /api/utm-asset-groups/searchGroupsByFilter endpoint, injecting arbitrary SQL commands. This vulnerability allows execution of SQL with DBA privileges, potentially leading to full database read, data modification, and filesystem access.

Join the discussion

UTMStack versions prior to 11.2.16 have a server-side request forgery (SSRF) vulnerability in the IdentityProviderService.validateMetadataUrl() function. This flaw allows authenticated attackers to supply a malicious metadata URL to the identity-providers endpoint, causing the server to send requests to arbitrary internal or cloud metadata hosts. The vulnerability affects the POST/PUT /api/identity-providers endpoint, which does not validate the target host, IP address, or URL scheme. Exploitation can enable internal network port scanning and access to cloud instance-metadata services.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Package: pkg:github/utmstack/UTMStack
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses