Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

wazuh — Vulnerabilities & Security Advisories 59

All 59 CVE vulnerabilities found in wazuh, with AI-generated Chinese analysis, references, and POCs.

This vulnerability aggregation page focuses on Wazuh, an open-source security monitoring platform developed by the Wazuh project. It collects documented security flaws affecting the Wazuh server, manager, and agent components, covering advisories published from 2019 through 2024. The data centers on common weakness classes such as remote code execution, privilege escalation, and buffer overflows in its logging and authentication modules. Readers can track the release cycle for specific Wazuh versions, analyze trends in weakness types over time, and review the product's historical exposure to critical vulnerabilities. Each entry links to the original advisory, vendor patch notes, and associated CVE records, allowing analysts to correlate impact, exploitability, and remediation status. The page is organized chronologically and by severity, enabling security teams to quickly identify which Wazuh releases addressed high-risk issues, particularly in areas like log ingestion, API access control, and agent communication channels. No single CVE ID is highlighted, but the collection provides a comprehensive view of how vulnerabilities in the Wazuh ecosystem evolved across its major release milestones.

Vendor: wazuh

CVE ID Title CVSS Severity Published
CVE-2026-61802 Wazuh discloses cleartext cluster key to low-privilege API users via GET /cluster/local/config CWE-200 6.5 Medium 2026-08-27
CVE-2026-61800 Wazuh cluster worker file sync allows arbitrary file write under /var/ossec (incomplete fix for CVE-2026-30893) CWE-22 9.1 Critical 2026-08-27
CVE-2026-61783 Wazuh: RBAC permission-effect check in mask_sensitive_config allows low-privilege users to read cluster.key CWE-200 7.0 High 2026-08-27
CVE-2026-54084 Wazuh agent enrollment NULL pointer dereference via malformed manager response CWE-476 5.3 Medium 2026-08-27
CVE-2026-54085 Wazuh: Missing input validation in multiple active response scripts allows argument injection CWE-88 7.1 High 2026-08-27
CVE-2026-54083 Wazuh: Path traversal in ip-customblock active response allows arbitrary file creation and deletion CWE-22 8.1 High 2026-08-27
CVE-2026-49392 Wazuh: Local SQL injection in FIM db due to path lookup interpolation in wazuh-syscheckd CWE-20 5.3 Medium 2026-08-19
CVE-2026-44256 Wazuh: CRLF Log Injection via Unsanitized Basic-Auth Username CWE-117 5.3 Medium 2026-08-19
CVE-2026-45798 Wazuh: Pre-auth stack-buffer-overflow in compare_wazuh_versions reachable from wazuh-authd (TCP/1515) via crafted enrollment V: field CWE-121 7.5 High 2026-08-19
CVE-2026-49441 Wazuh : peer-controlled metadata key in process_files_from_worker non-merged branch allows arbitrary file write under WAZUH_PATH on Wazuh manager CWE-73 9.1 Critical 2026-08-19
CVE-2026-41424 Wazuh: Privilege Escalation via Admin-Protection Bypass in update-user API Endpoint CWE-863 8.2 High 2026-08-19
CVE-2026-44255 Wazuh: Username Enumeration via Timing Side-Channel CWE-208 5.3 Medium 2026-08-19
CVE-2026-48024 Wazuh: merged-file header path traversal in cluster sync allows arbitrary file write under WAZUH_PATH in Wazuh manager CWE-22 9.1 Critical 2026-08-19
CVE-2026-48162 Wazuh: cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file path injection in Wazuh manager CWE-73 9.1 Critical 2026-08-19
CVE-2026-44901 Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability CWE-502 8.4 High 2026-08-19
CVE-2026-44254 Wazuh: Stack Out-of-Bounds Write in remoted Decompression Path CWE-131 5.3 Medium 2026-08-19
CVE-2026-46343 Wazuh: Arbitrary File Deletion via Cluster Protocol – Incomplete Path Validation in end_receiving_file() CWE-22 7.5 High 2026-08-19
CVE-2026-44253 Wazuh: Cluster Protocol Memory Exhaustion (DoS) via unbounded receive_str allocation and div_msg_box accumulation CWE-789 4.9 Medium 2026-08-19
CVE-2026-44252 Wazuh Manager dapi RBAC Bypass Allows Privilege Escalation CWE-863 7.7 High 2026-08-19
CVE-2026-67307 Wazuh before 5.0.0-beta3 Cluster Attribution Spoofing via Inventory Sync CWE-345 6.3 Medium 2026-08-01
CVE-2026-67308 Wazuh GitHub Actions Shell Injection via Fork Pull Request CWE-78 9.3 Critical 2026-08-01
CVE-2026-28220 Wazuh cluster DAPI arbitrary callable deserialization and RBAC context injection allow a cluster peer to execute privileged functions on the master node CWE-502 8.4 High 2026-07-20
CVE-2026-44251 Wazuh : size_t underflow in msgs.c ReadSecMSG causes wazuh-remoted DoS and potential heap overflow via crafted agent message CWE-122 6.5 Medium 2026-07-17
CVE-2026-40106 Wazuh: Heap-based Buffer Overflow in syscheck Registry Wildcard Expansion (LPE / DoS) CWE-122 4.7 Medium 2026-07-16
CVE-2026-39359 Wazuh: Unauthenticated Path Traversal in authd via Agent Group Name CWE-22 7.5 High 2026-07-16
CVE-2026-34150 Wazuh: Heap buffer overflow in wazuh-analysisd via rootcheck event parsing CWE-122 7.5 High 2026-07-16
CVE-2026-33754 Wazuh: Unauthenticated cluster packet length leads to uncontrolled memory allocation (remote DoS) CWE-400 6.5 Medium 2026-07-16
CVE-2026-33434 Wazuh: Rate Limit Bypass via /events Endpoint CWE-799 4.3 Medium 2026-07-16
CVE-2026-41499 Wazuh: Multiple Heap-based NULL WRITE Buffer Underflows in parse_uname_string() CWE-124 6.5 Medium 2026-04-29
CVE-2026-30893 Wazuh cluster sync path traversal in decompress_files() enables arbitrary file write and code execution from authenticated cluster peer CWE-22 9.0 Critical 2026-04-29

All 59 known CVE vulnerabilities affecting wazuh with full Chinese analysis, references, and POCs where available.