PT-2026-78513 · Wazuh · Wazuh

CVE-2026-49441

·

Published

2026-05-22

·

Updated

2026-08-19

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wazuh versions 4.3.0 through 4.14.5 Wazuh versions 5.0.0-beta1 through 5.0.0-beta2
Description The process files from worker() function in framework/wazuh/core/cluster/master.py trusts a peer-controlled file path key from files metadata.json. The destination is joined to WAZUH PATH without verifying that it remains within the directory selected by cluster item key. A cluster peer possessing the shared Fernet key can upload a crafted archive to overwrite security-sensitive files, such as /var/ossec/etc/ossec.conf. Modifying ossec.conf allows the configuration of root-executed commands, which can lead to remote code execution after a service reload.
Recommendations Update to version 4.14.6. Update to version 5.0.0-beta3.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12056
CVE-2026-49441
GHSA-3V57-HGVJ-3VJ2

Affected Products

Wazuh