8.2

CVE-2026-41424

Wazuh: Privilege Escalation via Admin-Protection Bypass in update-user API Endpoint

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.9.0 until 4.10.4 and 4.14.6, PUT /security/users/{user_id} in api/api/controllers/security_controller.py passes request.get("user") instead of request.context['token_info']['sub'] as current_user. remove_nones_to_dict() removes the resulting None value, so the reserved-account protection in framework/wazuh/security.py cannot verify who is making the request. An authenticated user with the users_admin role can overwrite the password of protected administrator accounts with user IDs at or below 99, including the wazuh superuser, and gain full administrative control. This issue is fixed in versions 4.10.4 and 4.14.6.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerwazuh
Produkt wazuh
Version >=4.9.0, < 4.10.4
Status affected
Version >= 4.11.0, < 4.14.6
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.266
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 8.2 2.3 5.3
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://github.com/wazuh/wazuh/releases/tag/v4.14.6
https://github.com/wazuh/wazuh/security/advisories/GHSA-gj9h-8hmr-xjjr
https://github.com/wazuh/wazuh/pull/35442
https://github.com/wazuh/wazuh/pull/35469
https://github.com/wazuh/wazuh/commit/1a38d11574c6d35a4272e1e7145d55d293e7dda4
https://github.com/wazuh/wazuh/commit/813add3575ecd4df484b2326715ca78f65505b4e
https://github.com/wazuh/wazuh/releases/tag/v4.10.4