Wazuh · Wazuh · CVE-2026-67307
**Name of the Vulnerable Software and Affected Versions**
Wazuh versions 5.0.0-beta1 through 5.0.0-beta2
**Description**
The software fails to validate or override the `cluster name` and `cluster node` fields in inventory-sync Start FlatBuffer messages, validating only the `agentid` against the authenticated agent identity. This allows a low-privileged enrolled agent to spoof cluster attribution in indexed inventory and vulnerability documents by forging `wazuh.cluster.name` values and influencing the document ` id` prefix. In shared-indexer multi-cluster deployments, this could lead to the poisoning of another cluster's records if numeric agent IDs collide, or the tampering of inventory records.
**Recommendations**
Update to version 5.0.0-beta3.