PT-2026-60121 · Opensearch+1 · Opensearch+1
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Wazuh Manager versions prior to 5.0.0-beta3
Description
The software fails to escape the
DataValue.index field when constructing OpenSearch bulk requests. This allows enrolled agents to inject arbitrary NDJSON (Newline Delimited JSON) operations. Attackers can smuggle delete, index, or update operations into bulk requests executed with the manager's admin credentials, which can lead to document deletion, alert tampering, and cross-agent SIEM state manipulation.Recommendations
Update Wazuh Manager to version 5.0.0-beta3 or later.
Exploit
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opensearch
Wazuh Manager