PT-2026-60606 · Wazuh · Wazuh

CVE-2026-33434

·

Published

2026-07-16

·

Updated

2026-07-20

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Wazuh versions 4.6.0 through 4.14.4
Description A logic error in the CheckRateLimitsMiddleware.dispatch() function allows event injection into analysisd by bypassing the global rate limit. Specifically, the rate check for the '/events' endpoint unconditionally overwrites the general rate limit result. Consequently, if the global max request per minute is exceeded, requests to the '/events' endpoint still succeed as long as the events-specific counter, which is hardcoded to 30 requests per minute, has not been reached.
Recommendations Update to version 4.14.5.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33434
GHSA-37QC-8242-6CRG

Affected Products

Wazuh