Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Jepalfer

#41243of 56,330
7.1Total CVSS
Vulnerabilities · 1
PT-2026-77250
7.1
2026-08-18
Wazuh · Wazuh · CVE-2026-74039
**Name of the Vulnerable Software and Affected Versions** Wazuh versions 4.0.0 through 4.14.6 Wazuh version 5.0.0-beta2 **Description** Authenticated attackers with `allow run as` enabled can cause a denial of service by exhausting CPU resources. This occurs when arbitrarily deeply nested JSON structures are submitted to the 'POST /security/user/authenticate/run as' endpoint. By repeatedly sending malformed `auth context` bodies with unlimited nesting depth, the API framework consumes excessive CPU, denying service to other API consumers. **Recommendations** Update Wazuh versions 4.0.0 through 4.14.6 to version 4.14.7. Update Wazuh version 5.0.0-beta2 to a newer version. As a temporary mitigation, disable the `allow run as` feature.