9.1

CVE-2026-48162

Exploit

Wazuh: cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file path injection in Wazuh manager

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, DistributedAPI.send_tmp_file() in framework/wazuh/core/cluster/dapi/dapi.py joins an attacker-controlled tmp_file value to WAZUH_PATH without canonicalization or confinement. A cluster peer holding the shared Fernet key can use traversal or an absolute path to make the master return any readable file over the cluster channel. Reading /var/ossec/api/configuration/security/private_key.pem allows the peer to forge administrator REST API tokens offline and then exercise administrative privileges without creating an account. This issue is fixed in versions 4.14.6 and 5.0.0-beta3.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wazuh ≫ Wazuh Version >= 4.0.0 < 4.14.6
Wazuh ≫ Wazuh Version 5.0.0 Update beta1
Wazuh ≫ Wazuh Version 5.0.0 Update beta2
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.63% 0.474
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 9.1 2.3 6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-73 External Control of File Name or Path

The product allows user input to control or influence paths or file names that are used in filesystem operations.

https://github.com/wazuh/wazuh/releases/tag/v5.0.0-beta3
Patch
Release Notes
https://github.com/wazuh/wazuh/releases/tag/v4.14.6
Patch
Release Notes
https://github.com/wazuh/wazuh/security/advisories/GHSA-r6f5-h662-8ffc
Vendor Advisory
Exploit
https://github.com/wazuh/wazuh/pull/36246
Patch
Issue Tracking
https://github.com/wazuh/wazuh/commit/de1eeedbe336744934be4e20d87d84a76e438cee
Patch