Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-61800— Wazuh cluster worker file sync allows arbitrary file write under /var/ossec (incomplete fix for CVE-2026-30893)

Quick assessment

Affected
wazuh wazuh
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Wazuh 是一个开源的安全平台,为端点和云工作负载提供统一的 XDR 和 SIEM 防护。在 Wazuh 4.4.0 到 4.14.6 版本中,持有集群密钥的一方可以在工作节点上对 目录下的任意文件进行写入、覆盖或删除操作,从而导致以 root 权限执行远程代码。 在集群文件同步过程中, 函数的非合并分支会将每个暂存文件移动到一个仅由 导出的目标路径,该函数虽然将路径限制在 目录下,但从未验证文件是否落在其 所声明的目录中。由于主节点上以及工作节点合并分支上存在的目标路径校验未被应用,对端节点可以将文件放置在攻击

CVSS 9.1 · Critical

Possible ATT&CK Techniques 2 AI

T1562 T1190.002
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-61800

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Wazuh cluster worker file sync allows arbitrary file write under /var/ossec (incomplete fix for CVE-2026-30893)
Source: CVE Program / CVE List V5
Vulnerability Description
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.4.0 through 4.14.6, a party holding the cluster key can write, overwrite, or delete arbitrary files under /var/ossec on worker nodes, leading to remote code execution as root. During cluster file synchronization, the non-merged branch of update_master_files_in_worker() moves each staged file to a destination derived only from safe_join(), which confines the path to /var/ossec but never verifies that the file lands in the directory declared by its cluster_item_key. Because the destination check present on the primary node and on the worker's merged branch was not applied, a peer can place files at attacker-chosen locations under /var/ossec, including paths that are executed as root, and the delete branch has the same gap. This is an incomplete fix for CVE-2026-30893, which addressed traversal outside /var/ossec but left this path able to redirect files anywhere within it. This issue is fixed in version 4.14.7.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
wazuh wazuh >= 4.4.0, < 4.14.7 -

II. Public POCs for CVE-2026-61800

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-61800

登录查看更多情报信息。

Patches & Fixes for CVE-2026-61800 (1)

Vendor Advisories for CVE-2026-61800 (1)

Same Patch Batch · wazuh · 2026-08-27 · 6 CVEs total

CVE-2026-54083 8.1 HIGH Wazuh: Path traversal in ip-customblock active response allows arbitrary file creation and
CVE-2026-54085 7.1 HIGH Wazuh: Missing input validation in multiple active response scripts allows argument inject
CVE-2026-61783 7.0 HIGH Wazuh: RBAC permission-effect check in mask_sensitive_config allows low-privilege users to
CVE-2026-61802 6.5 MEDIUM Wazuh discloses cleartext cluster key to low-privilege API users via GET /cluster/local/co
CVE-2026-54084 5.3 MEDIUM Wazuh agent enrollment NULL pointer dereference via malformed manager response

IV. Related Vulnerabilities

V. Comments for CVE-2026-61800

No comments yet


Leave a comment