PT-2026-67287 · Wazuh · Wazuh

·

CVE-2026-67307

·

Published

2026-08-01

·

Updated

2026-08-01

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Wazuh versions 5.0.0-beta1 through 5.0.0-beta2
Description The software fails to validate or override the cluster name and cluster node fields in inventory-sync Start FlatBuffer messages, validating only the agentid against the authenticated agent identity. This allows a low-privileged enrolled agent to spoof cluster attribution in indexed inventory and vulnerability documents by forging wazuh.cluster.name values and influencing the document id prefix. In shared-indexer multi-cluster deployments, this could lead to the poisoning of another cluster's records if numeric agent IDs collide, or the tampering of inventory records.
Recommendations Update to version 5.0.0-beta3.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67307
GHSA-JV5P-FHWH-9W55

Affected Products

Wazuh