PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-61802 wazuh CVE debrief

A low-privilege API user can read the cleartext cluster key from a configuration endpoint in Wazuh versions 4.14.0 through 4.14.6. The cluster key authenticates and encrypts traffic between cluster nodes, and disclosing it to an unprivileged account provides the authentication precondition for remote code execution chains. This issue is fixed in version 4.14.7.

Vendor
wazuh
Product
Unknown
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-28
Original CVE updated
2026-09-08
Advisory published
2026-08-28
Advisory updated
2026-09-08

Who should care

Defenders and security teams using Wazuh versions 4.14.0 through 4.14.6 should assess exposure and prioritize upgrading to version 4.14.7 or later. Security teams should verify exposure, restrict cluster:read permissions to necessary users, and monitor API user activity. Operators managing Wazuh deployments should review configuration and user permissions to prevent unauthorized access. Vulnerability management and security teams should consider compens

Why it matters

CVE-2026-61802 is a vulnerability in Wazuh that allows low-privilege API users to read the cleartext cluster key. Defenders should prioritize verifying exposure and upgrading to version 4.14.7 or later.

  • Unprivileged API users with cluster:read permissions can access the cleartext cluster key
  • Disclosure of the cluster key provides the authentication precondition for remote code execution chains
  • Defenders should verify exposure and upgrade to version 4.14.7 or later
  • Impact of unprivileged API users with cluster:read permissions requires assessment

Technical summary

The Wazuh security platform has a vulnerability in versions 4.14.0 through 4.14.6 where a low-privilege API user can read the cleartext cluster key from a configuration endpoint. The cluster key is used for authentication and encryption between cluster nodes. This issue allows unprivileged accounts with cluster:read permissions to access sensitive information, which can be used to authenticate and encrypt traffic between cluster nodes. Affected deployments should be identified, and defenders should prioritize verifying exposure and upgrading to version 4.14.7 or later.

Defensive priority

Defenders should prioritize verifying exposure and upgrading to version 4.14.7 or later. Assess the impact of unprivileged API users with cluster:read permissions.

Recommended defensive actions

  • Verify Wazuh version and assess exposure
  • Restrict cluster:read permissions to necessary users
  • Upgrade to version 4.14.7 or later
  • Monitor API user activity with cluster:read permissions
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. However, the scope of affected versions and potential impact require verification from official sources. Affected product deployments should be confirmed in managed environments, and an owner should be assigned for follow-up. The official advisory or CVE record should be reviewed to validate affected scope, severity, and vendor guidance. Vendors may have additional information on mitigations or patches. Security teams should verify exposure and consider compensating  

Sources and references

Verified primary and authoritative sources

  • CVE-2026-61802 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-61802

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-61802 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-61802

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.