PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-15612 Wazuh CVE debrief

CVE-2025-15612 is a medium-severity vulnerability in Wazuh provisioning scripts and Dockerfiles. The vulnerability causes insecure transport when using curl with the -k/--insecure flag, disabling SSL/TLS certificate validation. This allows attackers with network access to perform man-in-the-middle attacks, potentially leading to remote code execution and supply chain compromise during the build process.

Vendor
Wazuh
Product
Wazuh Provisioning Scripts (Agent Build Environment)
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-27
Original CVE updated
2026-09-30
Advisory published
2026-03-27
Advisory updated
2026-09-30

Who should care

DevOps teams, security teams, and IT administrators responsible for Wazuh deployments and build infrastructure should assess exposure and prioritize remediation. These teams need to verify Wazuh version and configuration, implement secure transport in build infrastructure, and monitor build processes for suspicious activity. They should also review compensating controls for exposed systems and track exceptions and retest remediated assets.

Why it matters

CVE-2025-15612 is a medium-severity vulnerability in Wazuh that allows for potential remote code execution and supply chain compromise during build processes. Defenders should prioritize verifying and remediating this vulnerability, especially in exposed environments.

  • Potential for remote code execution during build processes
  • Risk of supply chain compromise through modified dependencies
  • Need for verification of Wazuh version and configuration
  • Priority for implementing secure transport in build infrastructure

Technical summary

The vulnerability exists in Wazuh provisioning scripts and Dockerfiles, where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. This allows attackers with network access to perform man-in-the-middle attacks, potentially leading to remote code execution and supply chain compromise during the build process. The vulnerability causes insecure transport when using curl with the -k/--insecure flag, disabling SSL/TLS certificate validation. This allows attackers with network access to perform man-in-the-middle attacks, potentially leading to remote code execution and supply chain compromise during the build process. Wazuh deployments and build infrastructure are affected.

Defensive priority

Defenders should prioritize verifying and remediating this vulnerability in Wazuh deployments, especially in environments where build processes are exposed to untrusted networks.

Recommended defensive actions

  • Verify Wazuh deployments for vulnerable versions and configurations
  • Remediate by updating or patching affected Wazuh installations
  • Implement secure transport for build processes
  • Monitor build infrastructure for suspicious activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details about the vulnerability, including its description, CVSS score, and affected versions. Vendor advisories and third-party reports offer additional context. The vulnerability exists in Wazuh provisioning scripts and Dockerfiles, where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. This allows attackers with network access to perform man-in-the-middle attacks, potentially leading to remote code execution and supply chain compromise during the build. Def.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-15612 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-15612

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-15612 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15612

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/wazuh/wazuh/security/advisories/GHSA-wvg9-7q49-c7mg

    [email protected] - Exploit, Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/various-uses-of-curl-without-verifying-the-authenticity-of-the-ssl-certificate-leading-to-mitm-rce-in-build-infrastructure

    [email protected] - Third Party Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.