PT-2026-77250 · Wazuh · Wazuh

·

CVE-2026-74039

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Wazuh versions 4.0.0 through 4.14.6 Wazuh version 5.0.0-beta2
Description Authenticated attackers with allow run as enabled can cause a denial of service by exhausting CPU resources. This occurs when arbitrarily deeply nested JSON structures are submitted to the 'POST /security/user/authenticate/run as' endpoint. By repeatedly sending malformed auth context bodies with unlimited nesting depth, the API framework consumes excessive CPU, denying service to other API consumers.
Recommendations Update Wazuh versions 4.0.0 through 4.14.6 to version 4.14.7. Update Wazuh version 5.0.0-beta2 to a newer version. As a temporary mitigation, disable the allow run as feature.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74039
GHSA-5VH8-34R8-Q74Q

Affected Products

Wazuh