CVE-2026-48024
- EPSS 0.75%
- Veröffentlicht 19.08.2026 16:14:20
- Zuletzt bearbeitet 19.08.2026 17:18:51
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, cluster.unmerge_info() in framework/wazuh/core/cluster/cluster.py constructs paths from peer-controlled merge_type ...
CVE-2026-48162
- EPSS 0.63%
- Veröffentlicht 19.08.2026 16:13:15
- Zuletzt bearbeitet 19.08.2026 17:18:51
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, DistributedAPI.send_tmp_file() in framework/wazuh/core/cluster/dapi/dapi.py joins an attacker-controlled tmp_file v...
CVE-2026-44901
- EPSS 0.72%
- Veröffentlicht 19.08.2026 16:12:12
- Zuletzt bearbeitet 19.08.2026 18:16:39
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, AffectedItemsWazuhResult.merge() in framework/wazuh/core/results.py trusts the sort_casting field in a cluster work...
- EPSS 0.17%
- Veröffentlicht 01.08.2026 12:22:18
- Zuletzt bearbeitet 03.08.2026 19:16:50
Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_node fields in inventory-sync Start FlatBuffer messages, while validating only the agentid against the authenticated agent identity. This allows a low...
CVE-2026-67308
- EPSS 0.56%
- Veröffentlicht 01.08.2026 12:22:17
- Zuletzt bearbeitet 03.08.2026 20:17:26
Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters into e...
CVE-2026-28220
- EPSS 0.4%
- Veröffentlicht 20.07.2026 15:26:13
- Zuletzt bearbeitet 29.07.2026 15:37:36
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distributed API (DAPI) handling allow a cluster peer, or any actor able to authenticate to the cluster channe...
CVE-2026-44251
- EPSS 0.36%
- Veröffentlicht 17.07.2026 00:01:41
- Zuletzt bearbeitet 20.07.2026 02:22:10
Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t integer underflow in os_crypto/shared/msgs.c:389 allows any enrolled Wazuh agent to crash the wazuh-r...
CVE-2026-40106
- EPSS 0.13%
- Veröffentlicht 16.07.2026 23:57:16
- Zuletzt bearbeitet 20.07.2026 02:29:49
Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above prior to 4.14.5 contain a heap-based buffer overflow vulnerability in the syscheck component of the Wazuh agent for Windows. When e...
CVE-2026-39359
- EPSS 0.29%
- Veröffentlicht 16.07.2026 23:55:18
- Zuletzt bearbeitet 20.07.2026 13:42:42
Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through 4.10.3 and 4.11.0 through 4.14.4, a logic flaw affects the Wazuh Manager's enrollment daemon (authd) and synchronization daemon (r...
CVE-2026-34150
- EPSS 0.26%
- Veröffentlicht 16.07.2026 23:44:42
- Zuletzt bearbeitet 20.07.2026 13:36:42
Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 1.0.0 and above, prior to 4.14.5, a heap buffer overflow in wazuh-analysisd allows an unauthenticated remote attacker to crash the Wazuh manager...