UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated attackers to determine registered email addresses by observing differing HTTP responses from the POST /api/account/reset-password/init endpoint. Attackers can submit arbitrary email addresses and distinguish registered accounts, which return 200 OK, from unregistered accounts, which trigger a 500 Internal Server Error with backend error details, enabling targeted phishing or credential attacks.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-204"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82043.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82043.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "70773812559973059244528242160102601958",
"length": 3689
},
"id": "CVE-2026-82043-0793b236",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/utmstack/utmstack/commit/a310ff00d4f699cf0ae687573f43b69ad9906cdb",
"target": {
"file": "backend/src/main/java/com/park/utmstack/config/SecurityConfiguration.java",
"function": "configure"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"24314465636384831080084381857013409531",
"101145122101593491737521883455940834613",
"21943337672715565972139449547318075074",
"303463960373478848245061352223630480259"
],
"threshold": 0.9
},
"id": "CVE-2026-82043-f7b13804",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/utmstack/utmstack/commit/a310ff00d4f699cf0ae687573f43b69ad9906cdb",
"target": {
"file": "backend/src/main/java/com/park/utmstack/config/SecurityConfiguration.java"
}
}
]
"2026-10-03T14:01:36Z"