PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-48024 wazuh CVE debrief

A critical vulnerability exists in Wazuh, a free and open-source platform for threat prevention, detection, and response. The issue, tracked as CVE-2026-48024, allows a cluster peer with the shared Fernet key to write arbitrary files, including configuration files, through a path traversal vulnerability. This can lead to code execution when Wazuh services reload. The vulnerability affects Wazuh versions from 4.0.0 to 4.14.6 and 5.0.0-beta3. It has been fixed in versions 4.14.6 and 5.0.0-beta3.

Vendor
wazuh
Product
Unknown
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-19
Original CVE updated
2026-09-15
Advisory published
2026-08-19
Advisory updated
2026-09-15

Who should care

Defenders responsible for Wazuh installations, especially those with cluster peers having access to the shared Fernet key, should assess exposure and prioritize patching. Security teams should verify Wazuh configuration file integrity and monitor for suspicious activity.

Why it matters

CVE-2026-48024 is a critical vulnerability in Wazuh that allows a cluster peer to write arbitrary files, including configuration files, leading to potential code execution. Defenders should prioritize patching, verify configuration file integrity, and monitor for suspicious activity.

  • Code execution when Wazuh services reload.
  • Configuration file tampering leading to potential security bypass.
  • Potential for lateral movement within the cluster.
  • Verification of Wazuh configuration file integrity is required.

Technical summary

The vulnerability exists in the cluster.unmerge_info() function in framework/wazuh/core/cluster/cluster.py and the process_files_from_worker() function in framework/wazuh/core/cluster/master.py. A cluster peer with the shared Fernet key can use path traversal to write arbitrary files, including configuration files such as /var/ossec/etc/ossec.conf, which can configure root-executed commands and lead to code execution when Wazuh services reload. This issue affects Wazuh versions from 4.0.0 to 4.14.6 and 5.0.0-beta3, and has been fixed in versions 4.14.6 and 5.0.0-beta3.

Defensive priority

Defenders should prioritize patching vulnerable Wazuh instances, especially in environments where cluster peers have access to the shared Fernet key. They should also verify the integrity of Wazuh configuration files and monitor for suspicious activity.

Recommended defensive actions

  • Patch vulnerable Wazuh instances to versions 4.14.6 or 5.0.0-beta3.
  • Verify the integrity of Wazuh configuration files.
  • Monitor for suspicious activity in Wazuh cluster environments.
  • Restrict access to the shared Fernet key.
  • Implement additional security measures to detect and prevent exploitation.

Evidence notes

The vulnerability is caused by inadequate path confinement in the process_files_from_worker() function in framework/wazuh/core/cluster/master.py. A cluster peer can use traversal in files_metadata.json or a merged-file header to write files such as /var/ossec/etc/ossec.conf, which can configure root-executed commands and lead to code execution.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-48024 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-48024

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-48024 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48024

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.