8.2

CVE-2026-41424

Exploit

Wazuh: Privilege Escalation via Admin-Protection Bypass in update-user API Endpoint

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.9.0 until 4.10.4 and 4.14.6, PUT /security/users/{user_id} in api/api/controllers/security_controller.py passes request.get("user") instead of request.context['token_info']['sub'] as current_user. remove_nones_to_dict() removes the resulting None value, so the reserved-account protection in framework/wazuh/security.py cannot verify who is making the request. An authenticated user with the users_admin role can overwrite the password of protected administrator accounts with user IDs at or below 99, including the wazuh superuser, and gain full administrative control. This issue is fixed in versions 4.10.4 and 4.14.6.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wazuh ≫ Wazuh Version >= 4.9.0 < 4.10.4
Wazuh ≫ Wazuh Version >= 4.11.0 < 4.14.6
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.266
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 8.2 2.3 5.3
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://github.com/wazuh/wazuh/releases/tag/v4.14.6
Release Notes
https://github.com/wazuh/wazuh/security/advisories/GHSA-gj9h-8hmr-xjjr
Vendor Advisory
Exploit
https://github.com/wazuh/wazuh/pull/35442
Patch
Issue Tracking
https://github.com/wazuh/wazuh/pull/35469
Patch
Issue Tracking
https://github.com/wazuh/wazuh/commit/1a38d11574c6d35a4272e1e7145d55d293e7dda4
Patch
https://github.com/wazuh/wazuh/commit/813add3575ecd4df484b2326715ca78f65505b4e
Patch
https://github.com/wazuh/wazuh/releases/tag/v4.10.4
Release Notes