PT-2026-77250 · Wazuh · Wazuh
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Wazuh versions 4.0.0 through 4.14.6
Wazuh version 5.0.0-beta2
Description
Authenticated attackers with
allow run as enabled can cause a denial of service by exhausting CPU resources. This occurs when arbitrarily deeply nested JSON structures are submitted to the 'POST /security/user/authenticate/run as' endpoint. By repeatedly sending malformed auth context bodies with unlimited nesting depth, the API framework consumes excessive CPU, denying service to other API consumers.Recommendations
Update Wazuh versions 4.0.0 through 4.14.6 to version 4.14.7.
Update Wazuh version 5.0.0-beta2 to a newer version.
As a temporary mitigation, disable the
allow run as feature.Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wazuh