8.4

CVE-2026-44901

Exploit

Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, AffectedItemsWazuhResult.merge() in framework/wazuh/core/results.py trusts the sort_casting field in a cluster worker's JSON response. During a distributed API merge, attacker-controlled type names are resolved through Python builtins without an allowlist. A compromised worker can set sort_casting to exec and place Python source in affected_items, causing the master to execute the payload as root when responses from multiple nodes are merged. This issue is fixed in versions 4.14.6 and 5.0.0-beta2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wazuh ≫ Wazuh Version >= 4.0.0 < 4.14.6
Wazuh ≫ Wazuh Version 5.0.0 Update beta1
Wazuh ≫ Wazuh Version 5.0.0 Update beta2
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.72% 0.51
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 8.4 1.7 6
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

https://github.com/wazuh/wazuh/releases/tag/v4.14.6
Patch
Release Notes
https://github.com/wazuh/wazuh/releases/tag/v5.0.0-beta2
Patch
Release Notes
https://github.com/wazuh/wazuh/pull/35757
Patch
Issue Tracking
https://github.com/wazuh/wazuh/security/advisories/GHSA-8c6v-7g3w-prrq
Vendor Advisory
Exploit
https://github.com/wazuh/wazuh/commit/b29849f8abb08d78f257e6106b6111a8a1b0e621
Patch