PT-2026-98198 · Wazuh · Wazuh

CVE-2026-61811

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wazuh versions 3.8.0 through 4.14.6
Description The getattributes() function in src/os xml/os xml.c recursively processes XML attributes without a depth limit and allocates two large local buffers in each stack frame. An enrolled agent can submit a Windows EventChannel event containing an element with a high number of attributes to exhaust the analysisd worker-thread stack. This leads to a segmentation fault—a memory access violation that causes a program to crash—and interrupts log ingestion. The depth limit in the ReadElem() function does not restrict the number of attributes on a single element, failing to prevent this condition.
Recommendations Update to version 4.14.7.

Exploit

Fix

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61811
GHSA-9WV5-7QWX-M9W5

Affected Products

Wazuh