Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 04 Oct 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Utmstack
Utmstack utmstack |
|
| Vendors & Products |
Utmstack
Utmstack utmstack |
Fri, 02 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | UTMStack before 11.2.16 contains a JPQL injection vulnerability that allows authenticated attackers to read arbitrary entity data by exploiting UtmNetworkScanService.searchPropertyValues(), which builds a JPQL query with String.format() and executes it via em.createQuery() without parameter binding. Attackers can inject malicious JPQL through the value parameter in the GET /api/utm-network-scans/searchPropertyValues endpoint to extract sensitive data including credential tables such as jhi_user. | |
| Title | UTMStack < 11.2.16 JPQL Injection via searchPropertyValues | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-05T20:30:21.937Z
Reserved: 2026-08-27T21:39:20.461Z
Link: CVE-2026-82045
Updated: 2026-10-05T19:18:45.538Z
Status : Deferred
Published: 2026-10-02T21:16:57.080
Modified: 2026-10-06T15:25:00.650
Link: CVE-2026-82045
No data.
OpenCVE Enrichment
Updated: 2026-10-04T20:52:51Z
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')