Wazuh 是一个开源安全平台,为端点和云工作负载提供统一的 XDR(扩展检测与响应)和 SIEM(安全信息与事件管理)防护。在 4.2.0 至 4.14.6 版本中,多个活动响应脚本将受攻击者影响的警报字段传递给具有特权(以 root 身份运行)的系统命令,而未对其格式进行校验,从而导致参数注入漏洞,影响作为 root 运行的工具。 在八个处理 字段的脚本中,有五个—— 、 、 、 和 ——省略了对非 IP 输入进行拒绝的 检查。此外, 脚本将 字段传递给 / 命令,仅通过与 "root" 进行简单比较来校验。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61800 | 9.1 CRITICAL | Wazuh cluster worker file sync allows arbitrary file write under /var/ossec (incomplete fi |
| CVE-2026-54083 | 8.1 HIGH | Wazuh: Path traversal in ip-customblock active response allows arbitrary file creation and |
| CVE-2026-61783 | 7.0 HIGH | Wazuh: RBAC permission-effect check in mask_sensitive_config allows low-privilege users to |
| CVE-2026-61802 | 6.5 MEDIUM | Wazuh discloses cleartext cluster key to low-privilege API users via GET /cluster/local/co |
| CVE-2026-54084 | 5.3 MEDIUM | Wazuh agent enrollment NULL pointer dereference via malformed manager response |
No comments yet