5.3

CVE-2026-49392

Exploit

Wazuh: Local SQL injection in FIM db due to path lookup interpolation in wazuh-syscheckd

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.6.0 until 4.14.6 and 5.0.0-beta3, DB::getFile() and DB::searchFile() in src/syscheckd/src/db/src/file.cpp concatenate a monitored file path into SQLite row filters. On non-Windows systems, FIMDBCreator::encodeString() does not escape the value. A local user who can create a filename in a File Integrity Monitoring directory can inject a UNION SELECT expression when wazuh-syscheckd processes or deletes that path. The confirmed primitive manipulates SELECT result sets consumed by the FIM code; stacked statements and remote code execution were not demonstrated. This issue is fixed in versions 4.14.6 and 5.0.0-beta3.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wazuh ≫ Wazuh Version >= 4.6.0 < 4.14.6
Wazuh ≫ Wazuh Version 5.0.0 Update beta1
Wazuh ≫ Wazuh Version 5.0.0 Update beta2
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.091
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 5.3 1.8 3.4
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

https://github.com/wazuh/wazuh/releases/tag/v5.0.0-beta3
Patch
Release Notes
https://github.com/wazuh/wazuh/releases/tag/v4.14.6
Patch
Release Notes
https://github.com/wazuh/wazuh/security/advisories/GHSA-9c4x-mrjh-rmw5
Vendor Advisory
Exploit
https://github.com/wazuh/wazuh/pull/36399
Patch
Issue Tracking
https://github.com/wazuh/wazuh/commit/8e4e25b971dfb7b15bc492f10f8a350e6b37e70e
Patch
Exploit