PatchSiren cyber security CVE debrief
CVE-2026-74038 Wazuh CVE debrief
CVE-2026-74038 is a path traversal vulnerability in Wazuh 4.0.0 before 4.14.6 that allows unauthenticated remote attackers to cause denial of service. The vulnerability is caused by insufficient validation in OS_IsValidName() and unsafe path concatenation in delete_diff(). Affected deployments should be identified and verified for exposure. Official guidance from the CVE record and NVD entry should be reviewed for validation and mitigation strategies. Compensating controls may be necessary for exposed systems until patches can be applied.
- Vendor
- Wazuh
- Product
- wazuh-manager
- CVSS
- HIGH 7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-09-08
Who should care
Defenders and administrators of Wazuh installations should assess exposure and prioritize patching to prevent denial of service attacks. Operators, platform administrators, and security teams may be impacted by this vulnerability and should review official guidance for validation and mitigation strategies.
Why it matters
CVE-2026-74038 is a path traversal vulnerability in Wazuh that allows unauthenticated remote attackers to cause denial of service. Defenders should prioritize verifying Wazuh versions and applying patches to prevent denial of service attacks.
- Denial of service attacks are possible
- Version verification and patching are required
- Monitoring for suspicious activity is necessary
Technical summary
The vulnerability is caused by insufficient validation in OS_IsValidName() and unsafe path concatenation in delete_diff(), allowing unauthenticated remote attackers to cause denial of service by enrolling an agent with a dot-sequence name. Affected product context indicates that Wazuh deployments should be verified for exposure. Defensive impact is significant, as denial of service attacks are possible. Source-grounded technical framing emphasizes the need for patching and compensating controls without unsupported root-cause or exploit claims.
Defensive priority
Defenders should prioritize verifying Wazuh versions and applying patches to prevent denial of service attacks.
Recommended defensive actions
- Verify Wazuh version and apply patches
- Monitor for suspicious activity
- Implement additional security measures
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions and retest remediated assets
- Confirm whether affected product deployments exist in managed environments
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but the scope of affected versions and potential impact require further verification. Defenders should verify Wazuh versions, assess exposure, and apply patches to prevent denial of service attacks. Evidence limits and source grounding indicate that additional verification is necessary to confirm affected scope and severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-74038 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-74038
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-74038 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-74038
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/wazuh/wazuh/pull/35833
-
Source reference
Unverified legacy reference
URL: https://github.com/wazuh/wazuh/security/advisories/GHSA-573w-mqw4-jvmr
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/wazuh-path-traversal-dos-via-agent-enrollment
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.