{"id":"CVE-2026-82043","summary":"UTMStack \u003c 11.2.16 Account Enumeration via Password Reset Endpoint","details":"UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated attackers to determine registered email addresses by observing differing HTTP responses from the POST /api/account/reset-password/init endpoint. Attackers can submit arbitrary email addresses and distinguish registered accounts, which return 200 OK, from unregistered accounts, which trigger a 500 Internal Server Error with backend error details, enabling targeted phishing or credential attacks.","modified":"2026-10-04T02:46:47.934157552Z","published":"2026-10-02T20:17:20.012Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-204"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82043.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82043.json"},{"type":"ADVISORY","url":"https://github.com/UTMStack/UTMStack/releases/tag/v11.2.16"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82043"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/utmstack-account-enumeration-via-password-reset-endpoint"},{"type":"FIX","url":"https://github.com/utmstack/UTMStack/commit/4e7a727c3b8d8e2ad020d3b4f982a6d085dbecdd"},{"type":"PACKAGE","url":"https://github.com/utmstack/UTMStack"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/utmstack/utmstack","events":[{"introduced":"0"},{"fixed":"a310ff00d4f699cf0ae687573f43b69ad9906cdb"},{"fixed":"4e7a727c3b8d8e2ad020d3b4f982a6d085dbecdd"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"11.2.16"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["v11.2.15","v11.2.14","v11.2.13","v11.2.12","v11.2.11","v11.2.10","v11.2.9","v11.2.8","v11.2.7","v11.2.6","v11.2.5","v11.2.4","v11.2.3","v11.2.2","v11.2.1","v11.2.0","v11.1.8","v11.1.7","v11.1.6","v11.1.5","v11.1.4","v11.1.3","v11.1.2","v11.1.1","v11.1.0","v11.0.3","v11.0.2","v11.0.1","v11.0.0","v11.0.0-beta.2","v11.0.0-beta.1","v10.4.3-202405302135","v10.4.2-202405091759","v10.4.1-202405031218","v10.4.1-202405031709","v10.4.0-202404241632","v10.2.3-202402162310","v10.1.0-202312131645","v10.1.0-202311061514"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82043.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}