UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated...

zetlyn/cve-ghsa vulnerability ghsa GHSA-62x9-x97p-5mj3 cve CVE-2026-82043 known 2026-10-02

https://github.com/advisories/GHSA-62x9-x97p-5mj3

Properties

cvss5.3
receipt
Source
GitHub advisories
Its words
5.3
Read by
field:cvss.score
Said since
2026-10-03 00:02 UTC
Last answered
2026-10-04 12:14 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-82043",
  "cvss": {
    "score": 5.3,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 5.3,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
    },
    "cvss_v4": {
      "score": 6.9,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-204",
      "name": "Observable Response Discrepancy"
    }
  ],
  "description": "UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated attackers to determine registered email addresses by observing differing HTTP responses from the POST /api/account/reset-password/init endpoint. Attackers can submit arbitrary email addresses and distinguish registered accounts, which return 200 OK, from unregistered accounts, which trigger a 500 Internal Server Error with backend error details, enabling targeted phishing or credential attacks.",
  "ghsa_id": "GHSA-62x9-x97p-5mj3",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-62x9-x97p-5mj3",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-62x9-x97p-5mj3"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-82043"
    }
  ],
  "nvd_published_at": "2026-10-02T21:16:56Z",
  "published_at": "2026-10-02T21:32:07Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-82043",
    "https://github.com/utmstack/UTMStack/commit/4e7a727c3b8d8e2ad020d3b4f982a6d085dbecdd",
    "https://github.com/UTMStack/UTMStack/releases/tag/v11.2.16",
    "https://www.vulncheck.com/advisories/utmstack-account-enumeration-via-password-reset-endpoint",
    "https://github.com/advisories/GHSA-62x9-x97p-5mj3"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated...",
  "type": "unreviewed",
  "updated_at": "2026-10-02T21:32:19Z",
  "url": "https://api.github.com/advisories/GHSA-62x9-x97p-5mj3",
  "vulnerabilities": [],
  "withdrawn_at": null
}
cweCWE-204
receipt
Source
GitHub advisories
Its words
CWE-204
Read by
field:cwes[].cwe_id
Said since
2026-10-03 00:02 UTC
Last answered
2026-10-04 12:14 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-82043",
  "cvss": {
    "score": 5.3,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 5.3,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
    },
    "cvss_v4": {
      "score": 6.9,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-204",
      "name": "Observable Response Discrepancy"
    }
  ],
  "description": "UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated attackers to determine registered email addresses by observing differing HTTP responses from the POST /api/account/reset-password/init endpoint. Attackers can submit arbitrary email addresses and distinguish registered accounts, which return 200 OK, from unregistered accounts, which trigger a 500 Internal Server Error with backend error details, enabling targeted phishing or credential attacks.",
  "ghsa_id": "GHSA-62x9-x97p-5mj3",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-62x9-x97p-5mj3",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-62x9-x97p-5mj3"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-82043"
    }
  ],
  "nvd_published_at": "2026-10-02T21:16:56Z",
  "published_at": "2026-10-02T21:32:07Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-82043",
    "https://github.com/utmstack/UTMStack/commit/4e7a727c3b8d8e2ad020d3b4f982a6d085dbecdd",
    "https://github.com/UTMStack/UTMStack/releases/tag/v11.2.16",
    "https://www.vulncheck.com/advisories/utmstack-account-enumeration-via-password-reset-endpoint",
    "https://github.com/advisories/GHSA-62x9-x97p-5mj3"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated...",
  "type": "unreviewed",
  "updated_at": "2026-10-02T21:32:19Z",
  "url": "https://api.github.com/advisories/GHSA-62x9-x97p-5mj3",
  "vulnerabilities": [],
  "withdrawn_at": null
}
severitymedium
receipt
Source
GitHub advisories
Its words
medium
Read by
field:severity
Said since
2026-10-03 00:02 UTC
Last answered
2026-10-04 12:14 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-82043",
  "cvss": {
    "score": 5.3,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 5.3,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
    },
    "cvss_v4": {
      "score": 6.9,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-204",
      "name": "Observable Response Discrepancy"
    }
  ],
  "description": "UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated attackers to determine registered email addresses by observing differing HTTP responses from the POST /api/account/reset-password/init endpoint. Attackers can submit arbitrary email addresses and distinguish registered accounts, which return 200 OK, from unregistered accounts, which trigger a 500 Internal Server Error with backend error details, enabling targeted phishing or credential attacks.",
  "ghsa_id": "GHSA-62x9-x97p-5mj3",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-62x9-x97p-5mj3",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-62x9-x97p-5mj3"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-82043"
    }
  ],
  "nvd_published_at": "2026-10-02T21:16:56Z",
  "published_at": "2026-10-02T21:32:07Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-82043",
    "https://github.com/utmstack/UTMStack/commit/4e7a727c3b8d8e2ad020d3b4f982a6d085dbecdd",
    "https://github.com/UTMStack/UTMStack/releases/tag/v11.2.16",
    "https://www.vulncheck.com/advisories/utmstack-account-enumeration-via-password-reset-endpoint",
    "https://github.com/advisories/GHSA-62x9-x97p-5mj3"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated...",
  "type": "unreviewed",
  "updated_at": "2026-10-02T21:32:19Z",
  "url": "https://api.github.com/advisories/GHSA-62x9-x97p-5mj3",
  "vulnerabilities": [],
  "withdrawn_at": null
}

Text

UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated... UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated attackers to determine registered email addresses by observing differing HTTP responses from the POST /api/account/reset-password/init endpoint. Attackers can submit arbitrary email addresses and distinguish registered accounts, which return 200 OK, from unregistered accounts, which trigger a 500 Internal Server Error with backend error details, enabling targeted phishing or credential attacks.