Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

wazuh — Vulnerabilities & Security Advisories 53

All 53 CVE vulnerabilities found in wazuh, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities associated with Wazuh, an open-source security monitoring platform, categorized under common weakness types such as cross-site scripting and privilege escalation. The collection includes detailed records of security flaws affecting Wazuh versions, covering the period from early releases up to the present day. By reviewing this data, users can track vendor advisories related to Wazuh to stay informed about critical patches, understand the prevalence and impact of specific weakness classes within the application, and look up the product’s vulnerability history to assess risk over time. The content is organized to facilitate efficient security assessment for system administrators and security analysts responsible for maintaining Wazuh deployments. Each entry provides essential context regarding the nature of the flaw, affected components, and recommended mitigation strategies. This resource aims to support proactive security management by centralizing information that might otherwise be scattered across various vendor announcements and database entries. The focus remains on factual reporting of identified issues without speculation or promotional language. Users can utilize this aggregation to prioritize remediation efforts based on severity and availability of fixes. The page serves as a reference point for understanding how vulnerabilities evolve within the Wazuh ecosystem and aids in making informed decisions about software updates and configuration hardening.

Vendor: wazuh

CVE ID Title CVSS Severity Published
CVE-2026-49392 Wazuh: Local SQL injection in FIM db due to path lookup interpolation in wazuh-syscheckd CWE-20 5.3 Medium 2026-08-19
CVE-2026-44256 Wazuh: CRLF Log Injection via Unsanitized Basic-Auth Username CWE-117 5.3 Medium 2026-08-19
CVE-2026-45798 Wazuh: Pre-auth stack-buffer-overflow in compare_wazuh_versions reachable from wazuh-authd (TCP/1515) via crafted enrollment V: field CWE-121 7.5 High 2026-08-19
CVE-2026-49441 Wazuh : peer-controlled metadata key in process_files_from_worker non-merged branch allows arbitrary file write under WAZUH_PATH on Wazuh manager CWE-73 9.1 Critical 2026-08-19
CVE-2026-41424 Wazuh: Privilege Escalation via Admin-Protection Bypass in update-user API Endpoint CWE-863 8.2 High 2026-08-19
CVE-2026-44255 Wazuh: Username Enumeration via Timing Side-Channel CWE-208 5.3 Medium 2026-08-19
CVE-2026-48024 Wazuh: merged-file header path traversal in cluster sync allows arbitrary file write under WAZUH_PATH in Wazuh manager CWE-22 9.1 Critical 2026-08-19
CVE-2026-48162 Wazuh: cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file path injection in Wazuh manager CWE-73 9.1 Critical 2026-08-19
CVE-2026-44901 Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability CWE-502 8.4 High 2026-08-19
CVE-2026-44254 Wazuh: Stack Out-of-Bounds Write in remoted Decompression Path CWE-131 5.3 Medium 2026-08-19
CVE-2026-46343 Wazuh: Arbitrary File Deletion via Cluster Protocol – Incomplete Path Validation in end_receiving_file() CWE-22 7.5 High 2026-08-19
CVE-2026-44253 Wazuh: Cluster Protocol Memory Exhaustion (DoS) via unbounded receive_str allocation and div_msg_box accumulation CWE-789 4.9 Medium 2026-08-19
CVE-2026-44252 Wazuh Manager dapi RBAC Bypass Allows Privilege Escalation CWE-863 7.7 High 2026-08-19
CVE-2026-67307 Wazuh before 5.0.0-beta3 Cluster Attribution Spoofing via Inventory Sync CWE-345 6.3 Medium 2026-08-01
CVE-2026-67308 Wazuh GitHub Actions Shell Injection via Fork Pull Request CWE-78 9.3 Critical 2026-08-01
CVE-2026-28220 Wazuh cluster DAPI arbitrary callable deserialization and RBAC context injection allow a cluster peer to execute privileged functions on the master node CWE-502 8.4 High 2026-07-20
CVE-2026-44251 Wazuh : size_t underflow in msgs.c ReadSecMSG causes wazuh-remoted DoS and potential heap overflow via crafted agent message CWE-122 6.5 Medium 2026-07-17
CVE-2026-40106 Wazuh: Heap-based Buffer Overflow in syscheck Registry Wildcard Expansion (LPE / DoS) CWE-122 4.7 Medium 2026-07-16
CVE-2026-39359 Wazuh: Unauthenticated Path Traversal in authd via Agent Group Name CWE-22 7.5 High 2026-07-16
CVE-2026-34150 Wazuh: Heap buffer overflow in wazuh-analysisd via rootcheck event parsing CWE-122 7.5 High 2026-07-16
CVE-2026-33754 Wazuh: Unauthenticated cluster packet length leads to uncontrolled memory allocation (remote DoS) CWE-400 6.5 Medium 2026-07-16
CVE-2026-33434 Wazuh: Rate Limit Bypass via /events Endpoint CWE-799 4.3 Medium 2026-07-16
CVE-2026-41499 Wazuh: Multiple Heap-based NULL WRITE Buffer Underflows in parse_uname_string() CWE-124 6.5 Medium 2026-04-29
CVE-2026-30893 Wazuh cluster sync path traversal in decompress_files() enables arbitrary file write and code execution from authenticated cluster peer CWE-22 9.0 Critical 2026-04-29
CVE-2026-28221 Wazuh: Pre-auth stack-based buffer overflow in wazuh-remoted print_hex_string() due to signed char promotion on x86_64 CWE-121 6.5 Medium 2026-04-29
CVE-2026-26206 Wazuh: API brute-force protection bypass via race condition in login attempt tracking CWE-307 6.5 Medium 2026-04-29
CVE-2026-26204 Wazuh: Heap-based NULL WRITE Buffer Underflow in GetAlertData CWE-124 4.4 Medium 2026-04-29
CVE-2023-7340 Wazuh authd service (os_auth) Heap-based Buffer Overflow CWE-125 3.5 Low 2026-03-27
CVE-2026-32984 Heap buffer overflow in wazuh-authd CWE-125 3.5 Low 2026-03-27
CVE-2026-25790 Wazuh has Stack-Based Buffer Overflow in Security Configuration Assessment JSON Parser CWE-121 4.9 Medium 2026-03-17

All 53 known CVE vulnerabilities affecting wazuh with full Chinese analysis, references, and POCs where available.