CVE-2026-82043

Source
https://cve.org/CVERecord?id=CVE-2026-82043
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82043.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82043
Published
2026-10-02T20:17:20Z
Modified
2026-10-03T14:01:36Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
UTMStack < 11.2.16 Account Enumeration via Password Reset Endpoint
Details

UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated attackers to determine registered email addresses by observing differing HTTP responses from the POST /api/account/reset-password/init endpoint. Attackers can submit arbitrary email addresses and distinguish registered accounts, which return 200 OK, from unregistered accounts, which trigger a 500 Internal Server Error with backend error details, enabling targeted phishing or credential attacks.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-204"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82043.json"
}
References

Affected packages

Git / github.com/utmstack/utmstack

Affected ranges

Type
GIT
Repo
https://github.com/utmstack/utmstack
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "11.2.16"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

v10.*
v10.1.0-202311061514
v10.1.0-202312131645
v10.2.3-202402162310
v10.4.0-202404241632
v10.4.1-202405031218
v10.4.1-202405031709
v10.4.2-202405091759
v10.4.3-202405302135
v11.*
v11.0.0
v11.0.0-beta.1
v11.0.0-beta.2
v11.0.1
v11.0.2
v11.0.3
v11.1.0
v11.1.1
v11.1.2
v11.1.3
v11.1.4
v11.1.5
v11.1.6
v11.1.7
v11.1.8
v11.2.0
v11.2.1
v11.2.10
v11.2.11
v11.2.12
v11.2.13
v11.2.14
v11.2.15
v11.2.2
v11.2.3
v11.2.4
v11.2.5
v11.2.6
v11.2.7
v11.2.8
v11.2.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82043.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "70773812559973059244528242160102601958",
            "length":  3689
        },
        "id":  "CVE-2026-82043-0793b236",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/utmstack/utmstack/commit/a310ff00d4f699cf0ae687573f43b69ad9906cdb",
        "target":  {
            "file":  "backend/src/main/java/com/park/utmstack/config/SecurityConfiguration.java",
            "function":  "configure"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "24314465636384831080084381857013409531",
                "101145122101593491737521883455940834613",
                "21943337672715565972139449547318075074",
                "303463960373478848245061352223630480259"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-82043-f7b13804",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/utmstack/utmstack/commit/a310ff00d4f699cf0ae687573f43b69ad9906cdb",
        "target":  {
            "file":  "backend/src/main/java/com/park/utmstack/config/SecurityConfiguration.java"
        }
    }
]
vanir_signatures_modified
"2026-10-03T14:01:36Z"