PT-2026-60121 · Opensearch+1 · Opensearch+1

·

CVE-2026-56699

·

Published

2026-06-08

·

Updated

2026-07-15

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Wazuh Manager versions prior to 5.0.0-beta3
Description The software fails to escape the DataValue.index field when constructing OpenSearch bulk requests. This allows enrolled agents to inject arbitrary NDJSON (Newline Delimited JSON) operations. Attackers can smuggle delete, index, or update operations into bulk requests executed with the manager's admin credentials, which can lead to document deletion, alert tampering, and cross-agent SIEM state manipulation.
Recommendations Update Wazuh Manager to version 5.0.0-beta3 or later.

Exploit

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09828
CVE-2026-56699
GHSA-FF9G-85JQ-R3G3

Affected Products

Opensearch
Wazuh Manager