PT-2026-60610 · Wazuh · Wazuh

CVE-2026-40106

·

Published

2026-07-16

·

Updated

2026-07-20

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wazuh versions 4.6.0 through 4.14.4
Description A heap-based buffer overflow exists in the syscheck component of the Wazuh agent for Windows. The issue occurs when the agent expands registry paths containing wildcards (* or ?), as it allocates a fixed-size heap buffer of 256 bytes. A low-privileged local attacker can trigger an out-of-bounds write during string concatenation by creating a registry subkey with the maximum allowed length of 255 characters within a monitored path. Because the wazuh-agent.exe process runs with NT AUTHORITYSYSTEM privileges, this can result in a silent Denial of Service or Local Privilege Escalation (LPE), which is the act of gaining higher-level permissions on a system.
Recommendations Update to version 4.14.5.

Exploit

Fix

LPE

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40106
GHSA-QVRC-PCFC-JHQC

Affected Products

Wazuh