CVE-2026-49392
- EPSS 0.19%
- Veröffentlicht 19.08.2026 16:22:49
- Zuletzt bearbeitet 19.08.2026 18:16:41
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.6.0 until 4.14.6 and 5.0.0-beta3, DB::getFile() and DB::searchFile() in src/syscheckd/src/db/src/file.cpp concatenate a monitored file path into SQLi...
CVE-2026-44256
- EPSS 0.29%
- Veröffentlicht 19.08.2026 16:21:49
- Zuletzt bearbeitet 19.08.2026 19:17:16
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.4.0 until 4.14.6 and 5.0.0-beta2, api/api/middlewares.py decodes the Basic authentication username before credential validation and passes it to the ...
CVE-2026-45798
- EPSS 0.89%
- Veröffentlicht 19.08.2026 16:20:54
- Zuletzt bearbeitet 19.08.2026 18:16:39
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.5.0 until 4.14.6 and 5.0.0-beta2, compare_wazuh_versions() in src/shared/version_op.c copies the attacker-controlled enrollment V: field into a 10-by...
CVE-2026-49441
- EPSS 0.75%
- Veröffentlicht 19.08.2026 16:19:37
- Zuletzt bearbeitet 19.08.2026 19:17:17
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.3.0 until 4.14.6 and 5.0.0-beta3, the non-merged branch of process_files_from_worker() in framework/wazuh/core/cluster/master.py trusts a peer-contro...
CVE-2026-41424
- EPSS 0.34%
- Veröffentlicht 19.08.2026 16:18:24
- Zuletzt bearbeitet 19.08.2026 17:18:47
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.9.0 until 4.10.4 and 4.14.6, PUT /security/users/{user_id} in api/api/controllers/security_controller.py passes request.get("user") instead of reques...
CVE-2026-46343
- EPSS 0.26%
- Veröffentlicht 19.08.2026 16:17:11
- Zuletzt bearbeitet 19.08.2026 18:16:40
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, WazuhCommon.end_receiving_file() in framework/wazuh/core/cluster/common.py allows a cluster-authenticated node to d...
CVE-2026-44252
- EPSS 0.31%
- Veröffentlicht 19.08.2026 16:17:10
- Zuletzt bearbeitet 19.08.2026 16:17:10
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.5, Wazuh Manager allows a low-privilege read-only API user with manager:read permission to retrieve the cluster key from the element i...
CVE-2026-44253
- EPSS 0.42%
- Veröffentlicht 19.08.2026 16:17:10
- Zuletzt bearbeitet 19.08.2026 16:17:10
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 3.9.0 until 4.14.5 and 5.0.0-beta2, the Wazuh cluster protocol in framework/wazuh/core/cluster/common.py allows an authenticated cluster node to exhaus...
CVE-2026-44254
- EPSS 0.35%
- Veröffentlicht 19.08.2026 16:17:10
- Zuletzt bearbeitet 19.08.2026 19:17:16
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 1.0.0 until 4.14.6 and 5.0.0-beta2, HandleSecureMessage() in src/remoted/secure.c passes a pointer inside its stack buffer to ReadSecMSG(), and src/os_...
CVE-2026-44255
- EPSS 0.46%
- Veröffentlicht 19.08.2026 16:15:19
- Zuletzt bearbeitet 19.08.2026 17:18:48
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, AuthenticationManager.check_user() in framework/wazuh/rbac/orm.py performs check_password_hash() only when the supp...