PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-74038 Wazuh CVE debrief

CVE-2026-74038 is a path traversal vulnerability in Wazuh 4.0.0 before 4.14.6 that allows unauthenticated remote attackers to cause denial of service. The vulnerability is caused by insufficient validation in OS_IsValidName() and unsafe path concatenation in delete_diff(). Affected deployments should be identified and verified for exposure. Official guidance from the CVE record and NVD entry should be reviewed for validation and mitigation strategies. Compensating controls may be necessary for exposed systems until patches can be applied.

Vendor
Wazuh
Product
wazuh-manager
CVSS
HIGH 7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-09-08
Advisory published
2026-08-18
Advisory updated
2026-09-08

Who should care

Defenders and administrators of Wazuh installations should assess exposure and prioritize patching to prevent denial of service attacks. Operators, platform administrators, and security teams may be impacted by this vulnerability and should review official guidance for validation and mitigation strategies.

Why it matters

CVE-2026-74038 is a path traversal vulnerability in Wazuh that allows unauthenticated remote attackers to cause denial of service. Defenders should prioritize verifying Wazuh versions and applying patches to prevent denial of service attacks.

  • Denial of service attacks are possible
  • Version verification and patching are required
  • Monitoring for suspicious activity is necessary

Technical summary

The vulnerability is caused by insufficient validation in OS_IsValidName() and unsafe path concatenation in delete_diff(), allowing unauthenticated remote attackers to cause denial of service by enrolling an agent with a dot-sequence name. Affected product context indicates that Wazuh deployments should be verified for exposure. Defensive impact is significant, as denial of service attacks are possible. Source-grounded technical framing emphasizes the need for patching and compensating controls without unsupported root-cause or exploit claims.

Defensive priority

Defenders should prioritize verifying Wazuh versions and applying patches to prevent denial of service attacks.

Recommended defensive actions

  • Verify Wazuh version and apply patches
  • Monitor for suspicious activity
  • Implement additional security measures
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions and retest remediated assets
  • Confirm whether affected product deployments exist in managed environments

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but the scope of affected versions and potential impact require further verification. Defenders should verify Wazuh versions, assess exposure, and apply patches to prevent denial of service attacks. Evidence limits and source grounding indicate that additional verification is necessary to confirm affected scope and severity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-74038 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-74038

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-74038 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-74038

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.