Wazuh 是一个开源安全平台,为端点和云工作负载提供统一的 XDR 和 SIEM 防护。在 4.14.0 至 4.14.6 版本中,经过身份验证的低权限用户可以读取集群密钥(cluster secret),因为用于屏蔽敏感值的逻辑会被任何 update-config RBAC 规则禁用,包括显式的拒绝规则。 装饰器仅在 返回 时应用屏蔽;然而,该门控机制只要存在 或 规则,就认为用户具备配置更新权限,而从未检查该规则的效果(effect)是允许(allow)还是拒绝(deny)。由于一条“拒绝”规则会作为一个真实
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61800 | 9.1 CRITICAL | Wazuh cluster worker file sync allows arbitrary file write under /var/ossec (incomplete fi |
| CVE-2026-54083 | 8.1 HIGH | Wazuh: Path traversal in ip-customblock active response allows arbitrary file creation and |
| CVE-2026-54085 | 7.1 HIGH | Wazuh: Missing input validation in multiple active response scripts allows argument inject |
| CVE-2026-61802 | 6.5 MEDIUM | Wazuh discloses cleartext cluster key to low-privilege API users via GET /cluster/local/co |
| CVE-2026-54084 | 5.3 MEDIUM | Wazuh agent enrollment NULL pointer dereference via malformed manager response |
No comments yet