These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A low-privilege API user can read the cleartext cluster key from a configuration endpoint in Wazuh versions 4.14.0 through 4.14.6. The cluster key authenticates and encrypts traffic between cluster nodes, and disclosing it to an unprivileged account provides the authentication precondition for remote code execution chains. This issue is fixed in version 4.14.7.
A critical vulnerability in Wazuh, an open-source security platform, allows remote code execution as root on worker nodes. The issue, present in versions 4.4.0 through 4.14.6, stems from improper file synchronization during cluster updates, enabling a party with the cluster key to write, overwrite, or delete arbitrary files under /var/ossec. This vulnerability is an incomplete fix for CVE-2026-30893 and h [truncated]
A vulnerability in Wazuh, an open-source security platform, allows an authenticated low-privilege user to read the cluster secret from the manager configuration due to a logic flaw in masking sensitive values. This issue affects versions 4.14.0 through 4.14.6 and is fixed in version 4.14.7. The vulnerability arises from the mask_sensitive_config() decorator incorrectly disabling masking of sensitive value [truncated]
Wazuh versions 4.2.0 through 4.14.6 have a vulnerability in multiple active response scripts that pass attacker-influenced alert fields to privileged system commands without validating their format. This allows argument injection into tools that run as root. The issue is fixed in version 4.14.7. Organizations should review their active response scripts, validate input, and implement additional logging and [truncated]
A vulnerability in Wazuh, an open-source security platform, allows a malicious enrollment manager to crash a Wazuh agent during enrollment by returning a malformed key response. This issue affects versions 4.0.0 through 4.14.6 and is fixed in version 4.14.7. The vulnerability is caused by a NULL pointer dereference in the w_enrollment_process_agent_key() routine, which splits the manager-provided key into [truncated]
A path traversal vulnerability exists in the ip-customblock active response script of Wazuh, an open-source security platform. This script is used for unified XDR and SIEM protection for endpoints and cloud workloads. The vulnerability allows an attacker to create or delete arbitrary files on the filesystem as root. The issue arises because the script builds a file path by directly concatenating the srcip [truncated]
A critical vulnerability was discovered in Wazuh, a free and open-source platform for threat prevention, detection, and response. The issue, tracked as CVE-2026-49441, affects Wazuh versions from 4.3.0 to 4.14.6 and 5.0.0-beta3. An attacker can exploit this vulnerability by uploading a crafted archive to overwrite security-sensitive files, potentially leading to code execution after a service reload.
A local user can inject a UNION SELECT expression when wazuh-syscheckd processes or deletes a monitored file path in Wazuh File Integrity Monitoring. The issue arises from DB::getFile() and DB::searchFile() in src/syscheckd/src/db/src/file.cpp concatenating a monitored file path into SQLite row filters without proper escaping on non-Windows systems. This issue is fixed in versions 4.14.6 and 5.0.0-beta3. [truncated]
A critical vulnerability was found in Wazuh, a free and open-source platform for threat prevention, detection, and response. The issue, tracked as CVE-2026-48162, allows an attacker to read any file on the system, including sensitive files such as private key files, by exploiting the DistributedAPI.send_tmp_file() function. This can lead to the creation of forged administrator REST API tokens, granting th [truncated]
A critical vulnerability exists in Wazuh, a free and open-source platform for threat prevention, detection, and response. The issue, tracked as CVE-2026-48024, allows a cluster peer with the shared Fernet key to write arbitrary files, including configuration files, through a path traversal vulnerability. This can lead to code execution when Wazuh services reload. The vulnerability affects Wazuh versions f [truncated]
A remote denial-of-service vulnerability exists in Wazuh versions from 4.5.0 until 4.14.6 and 5.0.0-beta2 due to improper handling of attacker-controlled version strings in the compare_wazuh_versions() function. This issue is reachable before authentication when anonymous TLS enrollment is enabled on TCP port 1515. The vulnerability allows an attacker to cause a denial of service by providing a specially [truncated]
A vulnerability in Wazuh, a free and open-source platform for threat prevention, detection, and response, allows an attacker to execute arbitrary Python code as root. This issue arises from the `AffectedItemsWazuhResult.merge()` function in `framework/wazuh/core/results.py`, which does not properly validate the `sort_casting` field in cluster worker JSON responses. An attacker can exploit this by setting [truncated]
An unauthenticated attacker can forge entries, obscure activity, or poison systems that consume the plain-text audit log by including carriage returns or line feeds in the Basic authentication username. This issue arises from the decoding of the Basic authentication username before credential validation and its inclusion in the plain-text API log without neutralizing control characters. The vulnerability [truncated]
CVE-2026-41424 is a high-severity vulnerability in Wazuh, a free and open-source platform for threat prevention, detection, and response. An authenticated user with the users_admin role can overwrite the password of protected administrator accounts, including the wazuh superuser, and gain full administrative control. This issue is fixed in versions 4.10.4 and 4.14.6.
A cluster-authenticated node can delete files outside the Wazuh installation directory due to a path traversal issue in WazuhCommon.end_receiving_file(). This vulnerability allows an attacker to target critical configuration files, potentially disabling the Wazuh manager, invalidating API tokens, or disrupting cluster and API connectivity. Wazuh users, especially those with cluster deployments, should ass [truncated]
A stack out-of-bounds write vulnerability exists in Wazuh's remoted daemon, which can be triggered by an encrypted agent message on TCP port 1514. This issue affects Wazuh versions from 1.0.0 to 4.14.6 and 5.0.0-beta2. The vulnerability can cause potential disruptions to agent communications and crashes of message processing in the root-level remoted daemon. Defenders responsible for Wazuh installations s [truncated]
A memory exhaustion vulnerability exists in Wazuh cluster protocol versions from 3.9.0 until 4.14.5 and 5.0.0-beta2. An authenticated cluster node can exploit this by sending a new_str command with an attacker-controlled total for InBuffer, causing the master to exhaust memory. This can disrupt agent connectivity and alert processing across the monitored environment.
A low-privilege read-only API user with manager:read permission in Wazuh Manager versions 4.0.0 to 4.14.5 can retrieve the cluster key, allowing an attacker with network access to TCP port 1516 to impersonate a cluster worker and submit distributed API requests with attacker-controlled rbac_permissions. This vulnerability enables unauthorized access, impersonation, and potential creation of users with adm [truncated]
A denial of service vulnerability exists in Wazuh 4.4.0 before 4.14.7 in the fdecompress_files() function within cluster.py. Authenticated cluster peers can exhaust memory by supplying a malicious synchronization archive without decompressed size limits, using a small, highly compressed zip bomb archive that forces wazuh-clusterd on the master node to decompress the full payload into memory, causing memor [truncated]
CVE-2026-74044 Wazuh path traversal vulnerability allows authenticated cluster peers to delete arbitrary directory contents. Attackers with a valid cluster Fernet key can craft a malicious node name, disconnect, and trigger the master's peer cleanup routine to remove arbitrary directories within the Wazuh installation path writable by the wazuh user.
CVE-2026-74039 is a high-severity denial of service vulnerability affecting Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2. Authenticated attackers with allow_run_as enabled can exhaust CPU resources by submitting deeply nested JSON structures to the POST /security/user/authenticate/run_as endpoint, impacting API consumers. This vulnerability allows attackers to cause excessive CPU consumption, denying service [truncated]
A path traversal vulnerability exists in Wazuh 4.0.0 before 4.14.6, allowing unauthenticated remote attackers to cause denial of service by enrolling an agent with a malicious name. This vulnerability can lead to the removal of subdirectories and the stopping of Wazuh services, requiring manual recovery. The vulnerability is caused by insufficient validation in OS_IsValidName() and unsafe path concatenati [truncated]
The CVE-2026-67308 vulnerability exists in Wazuh workflows before version 44bf114, where a shell injection vulnerability in GitHub Actions allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. This vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Security teams and administrators responsible for Wazuh workflows and GitHub Actions should [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T13:17:00.403Z and has not been modified since then. The Wazuh 5.0.0-beta1 version does not validate or override the cluster_name and cluster_node fields in inventory-sync Start FlatBuffer messages, allowing a low-privileged enrolled agent to spoof cluster attribution in indexed inventory and vuln [truncated]
CVE-2026-44251 is a remote denial of service vulnerability in Wazuh versions 3.0.0 and above, prior to 4.14.5. A size_t integer underflow in os_crypto/shared/msgs.c:389 allows any enrolled Wazuh agent to crash the wazuh-remoted process on the manager, immediately disconnecting all agents from the manager. A second code path reached by the same underflow may allow heap memory corruption. The issue has been [truncated]
A heap-based buffer overflow vulnerability exists in the syscheck component of the Wazuh agent for Windows, versions 4.6.0 and above prior to 4.14.5. The vulnerability occurs when expanding registry paths containing wildcards (* or ?). A low-privileged local attacker can force an out-of-bounds write during string concatenation, potentially leading to a Denial of Service (DoS) or Local Privilege Escalation [truncated]
A logic flaw was found in the Wazuh Manager's enrollment daemon (authd) and synchronization daemon (remoted). The authd process allows agents to select a group during enrollment but does not filter path traversal sequences. This issue has been fixed in versions 4.10.4 and 4.14.5. The vulnerability affects Wazuh Manager versions 4.0.0 through 4.10.3 and 4.11.0 through 4.14.4, and it has the potential to ex [truncated]
A heap buffer overflow vulnerability exists in Wazuh's wazuh-analysisd component, which allows an unauthenticated remote attacker to crash the Wazuh manager's analysis engine, causing a complete loss of SIEM alert processing. The vulnerability is exploitable via the default configuration shipped in the official wazuh/wazuh-docker deployment. An attacker can enroll with authd without a password to obtain a [truncated]
CVE-2026-33754 is a denial of service vulnerability in Wazuh's cluster protocol parser. A remote attacker can trigger memory exhaustion by sending a crafted message header with an arbitrarily large payload length, allowing unauthenticated denial of service of the cluster service. This issue affects Wazuh versions 3.9.0 and above, prior to 4.14.5. Users should apply the patch to prevent denial of service a [truncated]
CVE-2026-33434 is a medium-severity vulnerability in Wazuh, a free and open-source platform for threat prevention, detection, and response. The issue allows for event injection into analysisd beyond the admin-configured global rate limit due to a logic error in CheckRateLimitsMiddleware.dispatch(). Affected product deployments should be reviewed for potential exposure, and rate limit configurations should [truncated]