PT-2026-78523 · Wazuh · Wazuh
CVE-2026-49392
·
Published
2026-08-19
·
Updated
2026-08-19
CVSS v3.1
5.3
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Wazuh versions 4.6.0 through 4.14.5
Wazuh versions 5.0.0-beta1 through 5.0.0-beta2
Description
In non-Windows systems, the
DB::getFile() and DB::searchFile() functions in src/syscheckd/src/db/src/file.cpp concatenate monitored file paths into SQLite row filters. Because FIMDBCreator::encodeString() fails to escape the value, a local user with the ability to create a filename within a File Integrity Monitoring (FIM) directory can inject a UNION SELECT expression. This occurs when wazuh-syscheckd processes or deletes the path, allowing the manipulation of SELECT result sets used by the FIM code.Recommendations
Update to version 4.14.6.
Update to version 5.0.0-beta3.
Exploit
Fix
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wazuh