CVE-2026-44901
- EPSS 0.72%
- Veröffentlicht 19.08.2026 16:12:12
- Zuletzt bearbeitet 15.09.2026 19:28:41
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, AffectedItemsWazuhResult.merge() in framework/wazuh/core/results.py trusts the sort_casting field in a cluster work...
CVE-2026-74046
- EPSS 0.32%
- Veröffentlicht 18.08.2026 17:27:24
- Zuletzt bearbeitet 01.10.2026 16:17:53
Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability in the fdecompress_files() function within cluster.py that allows authenticated cluster peers to exhaust memory by supplying a malicious synchronization archive without decompressed...
- EPSS 0.38%
- Veröffentlicht 18.08.2026 17:26:50
- Zuletzt bearbeitet 01.10.2026 16:17:52
Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster peers to delete arbitrary directory contents by supplying a traversal-shaped node name in the cluster hello payload without validation. Attackers hold...
CVE-2026-74039
- EPSS 0.3%
- Veröffentlicht 18.08.2026 17:26:12
- Zuletzt bearbeitet 01.10.2026 16:17:52
Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allow_run_as enabled to exhaust CPU resources by submitting arbitrarily deeply nested JSON structures to the POST /security/u...
CVE-2026-74038
- EPSS 0.35%
- Veröffentlicht 18.08.2026 17:25:08
- Zuletzt bearbeitet 01.10.2026 16:17:52
Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause denial of service by enrolling an agent with a dot-sequence name such as ".." through the enrollment port. Attackers exploit insuf...
CVE-2026-67307
- EPSS 0.17%
- Veröffentlicht 01.08.2026 12:22:18
- Zuletzt bearbeitet 01.09.2026 15:41:39
Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_node fields in inventory-sync Start FlatBuffer messages, while validating only the agentid against the authenticated agent identity. This allows a low...
CVE-2026-67308
- EPSS 0.56%
- Veröffentlicht 01.08.2026 12:22:17
- Zuletzt bearbeitet 09.09.2026 20:26:18
Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters into e...
CVE-2026-28220
- EPSS 0.4%
- Veröffentlicht 20.07.2026 15:26:13
- Zuletzt bearbeitet 29.07.2026 15:37:36
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distributed API (DAPI) handling allow a cluster peer, or any actor able to authenticate to the cluster channe...
CVE-2026-44251
- EPSS 0.36%
- Veröffentlicht 17.07.2026 00:01:41
- Zuletzt bearbeitet 20.07.2026 02:22:10
Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t integer underflow in os_crypto/shared/msgs.c:389 allows any enrolled Wazuh agent to crash the wazuh-r...
CVE-2026-40106
- EPSS 0.13%
- Veröffentlicht 16.07.2026 23:57:16
- Zuletzt bearbeitet 20.07.2026 02:29:49
Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above prior to 4.14.5 contain a heap-based buffer overflow vulnerability in the syscheck component of the Wazuh agent for Windows. When e...