securityonline.info 8/11/2026, 2:11:05 AM · external

Critical Wazuh Flaws Allow Root Access via Cluster Key

Critical Wazuh Flaws Allow Root Access via Cluster Key
CyberSIXT Evidence Panel

THE article discusses three critical vulnerabilities in the Wazuh manager, each with a CVSS score of 9.1, affecting versions 4.0.0 and later. These vulnerabilities exploit the cluster protocol, allowing attackers with access to the shared Fernet key to achieve root code execution, read sensitive files, and forge admin tokens. The specific vulnerabilities are: 1. CVE-2026-49441: Arbitrary file write, allowing an attacker to overwrite the main ossec.conf file. 2.

CVE-2026-48162: Arbitrary file read, where attackers can read files and steal the REST API signing key. 3. CVE-2026-48024: Path traversal vulnerability, enabling unauthorized file writes. To mitigate these risks, users are advised to upgrade to version 4.14.6 or restrict network access to the cluster.

View Primary Source Via securityonline.info

Article by CyberSIXT