Wazuh 是一个开源的安全平台,为端点和云工作负载提供统一的 XDR 和 SIEM 防护。在 Wazuh 4.4.0 到 4.14.6 版本中,持有集群密钥的一方可以在工作节点上对 目录下的任意文件进行写入、覆盖或删除操作,从而导致以 root 权限执行远程代码。 在集群文件同步过程中, 函数的非合并分支会将每个暂存文件移动到一个仅由 导出的目标路径,该函数虽然将路径限制在 目录下,但从未验证文件是否落在其 所声明的目录中。由于主节点上以及工作节点合并分支上存在的目标路径校验未被应用,对端节点可以将文件放置在攻击
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54083 | 8.1 HIGH | Wazuh: Path traversal in ip-customblock active response allows arbitrary file creation and |
| CVE-2026-54085 | 7.1 HIGH | Wazuh: Missing input validation in multiple active response scripts allows argument inject |
| CVE-2026-61783 | 7.0 HIGH | Wazuh: RBAC permission-effect check in mask_sensitive_config allows low-privilege users to |
| CVE-2026-61802 | 6.5 MEDIUM | Wazuh discloses cleartext cluster key to low-privilege API users via GET /cluster/local/co |
| CVE-2026-54084 | 5.3 MEDIUM | Wazuh agent enrollment NULL pointer dereference via malformed manager response |
No comments yet