PatchSiren cyber security CVE debrief
CVE-2026-61802 wazuh CVE debrief
A low-privilege API user can read the cleartext cluster key from a configuration endpoint in Wazuh versions 4.14.0 through 4.14.6. The cluster key authenticates and encrypts traffic between cluster nodes, and disclosing it to an unprivileged account provides the authentication precondition for remote code execution chains. This issue is fixed in version 4.14.7.
- Vendor
- wazuh
- Product
- Unknown
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-28
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-08-28
- Advisory updated
- 2026-09-08
Who should care
Defenders and security teams using Wazuh versions 4.14.0 through 4.14.6 should assess exposure and prioritize upgrading to version 4.14.7 or later. Security teams should verify exposure, restrict cluster:read permissions to necessary users, and monitor API user activity. Operators managing Wazuh deployments should review configuration and user permissions to prevent unauthorized access. Vulnerability management and security teams should consider compens
Why it matters
CVE-2026-61802 is a vulnerability in Wazuh that allows low-privilege API users to read the cleartext cluster key. Defenders should prioritize verifying exposure and upgrading to version 4.14.7 or later.
- Unprivileged API users with cluster:read permissions can access the cleartext cluster key
- Disclosure of the cluster key provides the authentication precondition for remote code execution chains
- Defenders should verify exposure and upgrade to version 4.14.7 or later
- Impact of unprivileged API users with cluster:read permissions requires assessment
Technical summary
The Wazuh security platform has a vulnerability in versions 4.14.0 through 4.14.6 where a low-privilege API user can read the cleartext cluster key from a configuration endpoint. The cluster key is used for authentication and encryption between cluster nodes. This issue allows unprivileged accounts with cluster:read permissions to access sensitive information, which can be used to authenticate and encrypt traffic between cluster nodes. Affected deployments should be identified, and defenders should prioritize verifying exposure and upgrading to version 4.14.7 or later.
Defensive priority
Defenders should prioritize verifying exposure and upgrading to version 4.14.7 or later. Assess the impact of unprivileged API users with cluster:read permissions.
Recommended defensive actions
- Verify Wazuh version and assess exposure
- Restrict cluster:read permissions to necessary users
- Upgrade to version 4.14.7 or later
- Monitor API user activity with cluster:read permissions
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. However, the scope of affected versions and potential impact require verification from official sources. Affected product deployments should be confirmed in managed environments, and an owner should be assigned for follow-up. The official advisory or CVE record should be reviewed to validate affected scope, severity, and vendor guidance. Vendors may have additional information on mitigations or patches. Security teams should verify exposure and consider compensating
Sources and references
Verified primary and authoritative sources
-
CVE-2026-61802 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-61802
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-61802 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-61802
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/wazuh/wazuh/commit/1c55af25ebb160bddbde591efc19bb77b01282e7
-
Source reference
Unverified legacy reference
URL: https://github.com/wazuh/wazuh/security/advisories/GHSA-chmg-89pf-2q82
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.