PT-2026-78504 · Wazuh · Wazuh Manager

CVE-2026-44252

·

Published

2026-04-15

·

Updated

2026-08-21

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Wazuh Manager versions 4.0.0 through 4.14.4
Description A low-privilege read-only API user with manager:read permission can retrieve the cluster key from the ossec.conf element via the 'GET /manager/configuration?raw=true' endpoint. An attacker with network access to TCP port 1516 can use this disclosed Fernet key (a symmetric encryption key used for secure data transmission) to impersonate a cluster worker. By submitting distributed API requests with attacker-controlled rbac permissions and rbac mode set to black, the attacker can exploit the master's trust in the worker-supplied authorization context. This allows for the creation of users, assignment of administrator roles, access to credentials and API tokens, modification of configuration, and execution of actions across agents.
Recommendations Update to version 4.14.5.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12057
CVE-2026-44252
GHSA-34FX-C2XW-XCPG

Affected Products

Wazuh Manager