PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-41424 wazuh CVE debrief

CVE-2026-41424 is a high-severity vulnerability in Wazuh, a free and open-source platform for threat prevention, detection, and response. An authenticated user with the users_admin role can overwrite the password of protected administrator accounts, including the wazuh superuser, and gain full administrative control. This issue is fixed in versions 4.10.4 and 4.14.6.

Vendor
wazuh
Product
Unknown
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-19
Original CVE updated
2026-09-18
Advisory published
2026-08-19
Advisory updated
2026-09-18

Who should care

Defenders and administrators of Wazuh installations should assess exposure and apply patches to prevent potential administrative control takeover. This includes reviewing the current Wazuh version, checking for vulnerability, and applying patches to affected versions. Additionally, defenders should restrict access to sensitive accounts and roles, monitor for suspicious activity, and review compensating controls for exposed systems.

Why it matters

CVE-2026-41424 is a high-severity vulnerability in Wazuh that allows an authenticated user to gain full administrative control. Defenders should prioritize verifying exposure and applying patches.

  • Potential takeover of administrative control
  • Elevation of privileges for authenticated users
  • Compromise of sensitive accounts
  • Verification of Wazuh version and patch level

Technical summary

The vulnerability exists in the PUT /security/users/{user_id} endpoint of Wazuh, where an authenticated user with the users_admin role can overwrite the password of protected administrator accounts, including the wazuh superuser, due to the use of request.get('user') instead of request.context['token_info']['sub'] as current_user. This allows for potential administrative control takeover. The issue is fixed in versions 4.10.4 and 4.14.6, and defenders should prioritize verifying exposure and applying patches to prevent potential administrative control takeover.

Defensive priority

Defenders should prioritize verifying exposure and applying patches to prevent potential administrative control takeover.

Recommended defensive actions

  • Verify Wazuh version and check if it is vulnerable
  • Apply patches to affected versions
  • Restrict access to sensitive accounts and roles
  • Monitor for suspicious activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability exists in Wazuh versions from 4.9.0 until 4.10.4 and 4.14.6. An authenticated user with the users_admin role can exploit this issue to gain full administrative control by overwriting the password of protected administrator accounts, including the wazuh superuser. This can be done through the PUT /security/users/{user_id} endpoint in api/api/controllers/security_controller.py, where the request.get('user') is used instead of request.context['token_info']['sub'] as current_user. The remove_nones_to_dict() function then

Sources and references

Verified primary and authoritative sources

  • CVE-2026-41424 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-41424

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-41424 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-41424

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.