Description
UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated attackers to determine registered email addresses by observing differing HTTP responses from the POST /api/account/reset-password/init endpoint. Attackers can submit arbitrary email addresses and distinguish registered accounts, which return 200 OK, from unregistered accounts, which trigger a 500 Internal Server Error with backend error details, enabling targeted phishing or credential attacks.
Published: 2026-10-02
Score: 6.9 Medium
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No solution or workaround provided in the CVE record.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 04 Oct 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Utmstack
Utmstack utmstack
Vendors & Products Utmstack
Utmstack utmstack

Fri, 02 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Description UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated attackers to determine registered email addresses by observing differing HTTP responses from the POST /api/account/reset-password/init endpoint. Attackers can submit arbitrary email addresses and distinguish registered accounts, which return 200 OK, from unregistered accounts, which trigger a 500 Internal Server Error with backend error details, enabling targeted phishing or credential attacks.
Title UTMStack < 11.2.16 Account Enumeration via Password Reset Endpoint
Weaknesses CWE-204
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-06T16:41:53.278Z

Reserved: 2026-08-27T21:39:20.461Z

Link: CVE-2026-82043

cve-icon Vulnrichment

Updated: 2026-10-06T16:41:48.986Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T21:16:56.790

Modified: 2026-10-06T17:17:27.543

Link: CVE-2026-82043

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T20:52:58Z

Weaknesses
  • CWE-204

    Observable Response Discrepancy