PT-2026-60608 · Wazuh · Wazuh

CVE-2026-34150

·

Published

2026-07-16

·

Updated

2026-07-17

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Wazuh versions 1.0.0 through 4.14.4
Description A heap buffer overflow in the wazuh-analysisd component allows an unauthenticated remote attacker to crash the analysis engine of the manager, resulting in a total loss of SIEM alert processing. This issue occurs when the official wazuh/wazuh-docker deployment is used with default configurations. An attacker can enroll via authd without a password to acquire a valid agent ID and encryption key, then connect to remoted using the Wazuh agent protocol. By injecting rootcheck events containing {key: value} patterns exceeding 30 bytes, the attacker triggers a sprintf overflow of a 30-byte buffer within the W JSON ParseRootcheck() function. This corrupts the heap and crashes wazuh-analysisd, causing alert processing to stop silently while the dashboard and API continue to display outdated data.
Recommendations Update to version 4.14.5.

Exploit

Fix

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10087
CVE-2026-34150
GHSA-RVR9-89Q8-W883

Affected Products

Wazuh