securityonline.info 11 Aug 2026, 01:30 UTC

Critical Wazuh Flaws Allow Root Access via Cluster Key

Critical Wazuh Flaws Allow Root Access via Cluster Key
CyberSIXT Evidence Panel
Primary Source github.com
CISA KEV Not in KEV
Patch Patch Status Unknown

THE article discusses three critical vulnerabilities in the Wazuh manager, each with a CVSS score of 9.1, affecting versions 4.0.0 and later. These vulnerabilities exploit the cluster protocol, allowing attackers with access to the shared Fernet key to achieve root code execution, read sensitive files, and forge admin tokens. The specific vulnerabilities are: 1. CVE-2026-49441: Arbitrary file write, allowing an attacker to overwrite the main ossec.conf file. 2.

CVE-2026-48162: Arbitrary file read, where attackers can read files and steal the REST API signing key. 3. CVE-2026-48024: Path traversal vulnerability, enabling unauthorized file writes. To mitigate these risks, users are advised to upgrade to version 4.14.6 or restrict network access to the cluster.

View Primary Source Via securityonline.info

Article by CyberSIXT