Wazuh 是一个开源安全平台,为端点和云工作负载提供统一的 XDR(扩展检测与响应)和 SIEM(安全信息与事件管理)保护。在 4.14.0 至 4.14.6 版本中,低权限的 API 用户可以从一个未对敏感信息进行掩码处理的配置端点读取明文的集群密钥。REST API 提供了一个名为 的掩码控制机制,用于对诸如 和 等敏感字段进行掩码处理,从而在响应中隐藏这些信息,适用于不具备 权限的用户。所有配置读取端点都应用了这一装饰器,但 端点是个例外。该端点由 支持,仅受 权限控制,并返回本地节点的集群配置,其中包括明
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61800 | 9.1 CRITICAL | Wazuh cluster worker file sync allows arbitrary file write under /var/ossec (incomplete fi |
| CVE-2026-54083 | 8.1 HIGH | Wazuh: Path traversal in ip-customblock active response allows arbitrary file creation and |
| CVE-2026-54085 | 7.1 HIGH | Wazuh: Missing input validation in multiple active response scripts allows argument inject |
| CVE-2026-61783 | 7.0 HIGH | Wazuh: RBAC permission-effect check in mask_sensitive_config allows low-privilege users to |
| CVE-2026-54084 | 5.3 MEDIUM | Wazuh agent enrollment NULL pointer dereference via malformed manager response |
No comments yet