PT-2026-78506 · Wazuh · Wazuh

CVE-2026-44254

·

Published

2026-08-19

·

Updated

2026-08-19

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wazuh versions 1.0.0 through 4.14.5 Wazuh versions 5.0.0-beta1 and earlier
Description A stack out-of-bounds write exists in the root-level remoted daemon. The HandleSecureMessage() function in src/remoted/secure.c passes a pointer inside its stack buffer to ReadSecMSG(), and src/os crypto/shared/msgs.c decompresses up to OS MAXSTR bytes at that offset. When an encrypted agent message on TCP port 1514 expands to 65,536 bytes, the os zlib uncompress() function writes a terminating null byte beyond the end of the destination buffer, which can crash message processing and disrupt agent communications.
Recommendations Update to version 4.14.6. Update to version 5.0.0-beta2.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44254
GHSA-9WM4-FP6C-HQGQ

Affected Products

Wazuh