PT-2026-60608 · Wazuh · Wazuh
CVE-2026-34150
·
Published
2026-07-16
·
Updated
2026-07-17
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Wazuh versions 1.0.0 through 4.14.4
Description
A heap buffer overflow in the
wazuh-analysisd component allows an unauthenticated remote attacker to crash the analysis engine of the manager, resulting in a total loss of SIEM alert processing. This issue occurs when the official wazuh/wazuh-docker deployment is used with default configurations. An attacker can enroll via authd without a password to acquire a valid agent ID and encryption key, then connect to remoted using the Wazuh agent protocol. By injecting rootcheck events containing {key: value} patterns exceeding 30 bytes, the attacker triggers a sprintf overflow of a 30-byte buffer within the W JSON ParseRootcheck() function. This corrupts the heap and crashes wazuh-analysisd, causing alert processing to stop silently while the dashboard and API continue to display outdated data.Recommendations
Update to version 4.14.5.
Exploit
Fix
DoS
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wazuh