PT-2026-77249 · Wazuh · Wazuh

·

CVE-2026-74038

·

Published

2026-08-18

·

Updated

2026-08-19

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Wazuh versions 4.0.0 through 4.14.5
Description An unauthenticated remote attacker can cause a denial of service by enrolling an agent using a dot-sequence name, such as .., via the enrollment port. This occurs due to insufficient validation in the OS IsValidName() function and unsafe path concatenation in the delete diff() function. These flaws allow a path traversal to the parent queue directory, resulting in the removal of its subdirectories and the shutdown of all services, which then require manual recovery.
Recommendations Update to version 4.14.6 or later.

Exploit

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74038
GHSA-573W-MQW4-JVMR

Affected Products

Wazuh