PT-2026-78504 · Wazuh · Wazuh Manager
CVE-2026-44252
·
Published
2026-04-15
·
Updated
2026-08-21
CVSS v4.0
7.7
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Wazuh Manager versions 4.0.0 through 4.14.4
Description
A low-privilege read-only API user with
manager:read permission can retrieve the cluster key from the ossec.conf element via the 'GET /manager/configuration?raw=true' endpoint. An attacker with network access to TCP port 1516 can use this disclosed Fernet key (a symmetric encryption key used for secure data transmission) to impersonate a cluster worker. By submitting distributed API requests with attacker-controlled rbac permissions and rbac mode set to black, the attacker can exploit the master's trust in the worker-supplied authorization context. This allows for the creation of users, assignment of administrator roles, access to credentials and API tokens, modification of configuration, and execution of actions across agents.Recommendations
Update to version 4.14.5.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wazuh Manager