PT-2026-82835 · Wazuh · Wazuh

·

CVE-2026-61800

·

Published

2026-08-18

·

Updated

2026-08-31

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wazuh versions 4.4.0 through 4.14.6
Description A flaw in the cluster file synchronization process allows an entity possessing the cluster key to write, overwrite, or delete arbitrary files within the /var/ossec directory on worker nodes, potentially resulting in remote code execution with root privileges. The issue occurs in the non-merged branch of the update master files in worker() function, where files are moved to a destination using safe join(). While this confines the path to /var/ossec, the system fails to verify if the file is placed in the directory specified by its cluster item key. This lack of destination verification, which is present on the primary node and the worker's merged branch, allows a peer to place files in attacker-controlled locations within /var/ossec that are executed as root. The delete branch contains the same deficiency.
Recommendations Update to version 4.14.7.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-13265
CVE-2026-61800
GHSA-3JFF-488G-335F

Affected Products

Wazuh