PatchSiren cyber security CVE debrief
CVE-2026-41424 wazuh CVE debrief
CVE-2026-41424 is a high-severity vulnerability in Wazuh, a free and open-source platform for threat prevention, detection, and response. An authenticated user with the users_admin role can overwrite the password of protected administrator accounts, including the wazuh superuser, and gain full administrative control. This issue is fixed in versions 4.10.4 and 4.14.6.
- Vendor
- wazuh
- Product
- Unknown
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-09-18
Who should care
Defenders and administrators of Wazuh installations should assess exposure and apply patches to prevent potential administrative control takeover. This includes reviewing the current Wazuh version, checking for vulnerability, and applying patches to affected versions. Additionally, defenders should restrict access to sensitive accounts and roles, monitor for suspicious activity, and review compensating controls for exposed systems.
Why it matters
CVE-2026-41424 is a high-severity vulnerability in Wazuh that allows an authenticated user to gain full administrative control. Defenders should prioritize verifying exposure and applying patches.
- Potential takeover of administrative control
- Elevation of privileges for authenticated users
- Compromise of sensitive accounts
- Verification of Wazuh version and patch level
Technical summary
The vulnerability exists in the PUT /security/users/{user_id} endpoint of Wazuh, where an authenticated user with the users_admin role can overwrite the password of protected administrator accounts, including the wazuh superuser, due to the use of request.get('user') instead of request.context['token_info']['sub'] as current_user. This allows for potential administrative control takeover. The issue is fixed in versions 4.10.4 and 4.14.6, and defenders should prioritize verifying exposure and applying patches to prevent potential administrative control takeover.
Defensive priority
Defenders should prioritize verifying exposure and applying patches to prevent potential administrative control takeover.
Recommended defensive actions
- Verify Wazuh version and check if it is vulnerable
- Apply patches to affected versions
- Restrict access to sensitive accounts and roles
- Monitor for suspicious activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability exists in Wazuh versions from 4.9.0 until 4.10.4 and 4.14.6. An authenticated user with the users_admin role can exploit this issue to gain full administrative control by overwriting the password of protected administrator accounts, including the wazuh superuser. This can be done through the PUT /security/users/{user_id} endpoint in api/api/controllers/security_controller.py, where the request.get('user') is used instead of request.context['token_info']['sub'] as current_user. The remove_nones_to_dict() function then
Sources and references
Verified primary and authoritative sources
-
CVE-2026-41424 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-41424
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-41424 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-41424
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/wazuh/wazuh/commit/1a38d11574c6d35a4272e1e7145d55d293e7dda4
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/wazuh/wazuh/commit/813add3575ecd4df484b2326715ca78f65505b4e
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/wazuh/wazuh/pull/35442
[email protected] - Issue Tracking, Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/wazuh/wazuh/pull/35469
[email protected] - Issue Tracking, Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/wazuh/wazuh/releases/tag/v4.10.4
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/wazuh/wazuh/releases/tag/v4.14.6
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/wazuh/wazuh/security/advisories/GHSA-gj9h-8hmr-xjjr
[email protected] - Exploit, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.