PatchSiren cyber security CVE debrief
CVE-2026-48024 wazuh CVE debrief
A critical vulnerability exists in Wazuh, a free and open-source platform for threat prevention, detection, and response. The issue, tracked as CVE-2026-48024, allows a cluster peer with the shared Fernet key to write arbitrary files, including configuration files, through a path traversal vulnerability. This can lead to code execution when Wazuh services reload. The vulnerability affects Wazuh versions from 4.0.0 to 4.14.6 and 5.0.0-beta3. It has been fixed in versions 4.14.6 and 5.0.0-beta3.
- Vendor
- wazuh
- Product
- Unknown
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-09-15
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-09-15
Who should care
Defenders responsible for Wazuh installations, especially those with cluster peers having access to the shared Fernet key, should assess exposure and prioritize patching. Security teams should verify Wazuh configuration file integrity and monitor for suspicious activity.
Why it matters
CVE-2026-48024 is a critical vulnerability in Wazuh that allows a cluster peer to write arbitrary files, including configuration files, leading to potential code execution. Defenders should prioritize patching, verify configuration file integrity, and monitor for suspicious activity.
- Code execution when Wazuh services reload.
- Configuration file tampering leading to potential security bypass.
- Potential for lateral movement within the cluster.
- Verification of Wazuh configuration file integrity is required.
Technical summary
The vulnerability exists in the cluster.unmerge_info() function in framework/wazuh/core/cluster/cluster.py and the process_files_from_worker() function in framework/wazuh/core/cluster/master.py. A cluster peer with the shared Fernet key can use path traversal to write arbitrary files, including configuration files such as /var/ossec/etc/ossec.conf, which can configure root-executed commands and lead to code execution when Wazuh services reload. This issue affects Wazuh versions from 4.0.0 to 4.14.6 and 5.0.0-beta3, and has been fixed in versions 4.14.6 and 5.0.0-beta3.
Defensive priority
Defenders should prioritize patching vulnerable Wazuh instances, especially in environments where cluster peers have access to the shared Fernet key. They should also verify the integrity of Wazuh configuration files and monitor for suspicious activity.
Recommended defensive actions
- Patch vulnerable Wazuh instances to versions 4.14.6 or 5.0.0-beta3.
- Verify the integrity of Wazuh configuration files.
- Monitor for suspicious activity in Wazuh cluster environments.
- Restrict access to the shared Fernet key.
- Implement additional security measures to detect and prevent exploitation.
Evidence notes
The vulnerability is caused by inadequate path confinement in the process_files_from_worker() function in framework/wazuh/core/cluster/master.py. A cluster peer can use traversal in files_metadata.json or a merged-file header to write files such as /var/ossec/etc/ossec.conf, which can configure root-executed commands and lead to code execution.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-48024 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-48024
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-48024 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48024
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/wazuh/wazuh/commit/88fc89fdfb1bf37b9d826e9c281a3d22655733de
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/wazuh/wazuh/pull/36204
[email protected] - Issue Tracking, Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/wazuh/wazuh/releases/tag/v4.14.6
[email protected] - Patch, Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/wazuh/wazuh/releases/tag/v5.0.0-beta3
[email protected] - Patch, Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/wazuh/wazuh/security/advisories/GHSA-gh4h-fx78-q8xc
[email protected] - Exploit, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.