Wazuh · Wazuh · CVE-2026-74039
**Name of the Vulnerable Software and Affected Versions**
Wazuh versions 4.0.0 through 4.14.6
Wazuh version 5.0.0-beta2
**Description**
Authenticated attackers with `allow run as` enabled can cause a denial of service by exhausting CPU resources. This occurs when arbitrarily deeply nested JSON structures are submitted to the 'POST /security/user/authenticate/run as' endpoint. By repeatedly sending malformed `auth context` bodies with unlimited nesting depth, the API framework consumes excessive CPU, denying service to other API consumers.
**Recommendations**
Update Wazuh versions 4.0.0 through 4.14.6 to version 4.14.7.
Update Wazuh version 5.0.0-beta2 to a newer version.
As a temporary mitigation, disable the `allow run as` feature.