PT-2026-82835 · Wazuh · Wazuh
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Wazuh versions 4.4.0 through 4.14.6
Description
A flaw in the cluster file synchronization process allows an entity possessing the cluster key to write, overwrite, or delete arbitrary files within the
/var/ossec directory on worker nodes, potentially resulting in remote code execution with root privileges. The issue occurs in the non-merged branch of the update master files in worker() function, where files are moved to a destination using safe join(). While this confines the path to /var/ossec, the system fails to verify if the file is placed in the directory specified by its cluster item key. This lack of destination verification, which is present on the primary node and the worker's merged branch, allows a peer to place files in attacker-controlled locations within /var/ossec that are executed as root. The delete branch contains the same deficiency.Recommendations
Update to version 4.14.7.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wazuh