PT-2026-82773 · Wazuh · Wazuh

·

CVE-2026-61783

·

Published

2026-08-18

·

Updated

2026-09-10

CVSS v4.0

7.0

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Wazuh versions 4.14.0 through 4.14.6
Description An authenticated low-privilege user can read the cluster secret from the manager configuration. This occurs because the logic used to mask sensitive values is disabled whenever any update-config Role-Based Access Control (RBAC) rule exists, regardless of whether the rule is set to allow or deny. Specifically, the mask sensitive config() decorator only applies masking if the has update permissions() function returns false. However, has update permissions() considers a user to have update permissions if a manager:update config or cluster:update config rule is present, failing to verify the rule's actual effect. Consequently, an account explicitly denied configuration edits is incorrectly treated as having update permissions, disabling the masking. An authenticated GET request to the configuration endpoint using the raw=true parameter can then return the ossec.conf XML file containing the cluster.key in clear text.
Recommendations Update to version 4.14.7.

Exploit

Fix

Information Disclosure

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-13264
CVE-2026-61783
GHSA-VJCQ-CF36-F5GX

Affected Products

Wazuh