CVEs we hold for Wazuh
Records whose assigning authority named Wazuh as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-74044Wazuh 4.0.0 < 4.14.6 Path Traversal Arbitrary Directory Deletion via Cluster Hellowazuh-manager
CVE-2026-61802Wazuh discloses cleartext cluster key to low-privilege API users via GET /cluster/local/configwazuh
CVE-2026-61800Wazuh cluster worker file sync allows arbitrary file write under /var/ossec (incomplete fix for CVE-2026-30893)wazuh
CVE-2026-61783Wazuh: RBAC permission-effect check in mask_sensitive_config allows low-privilege users to read cluster.keywazuh
CVE-2026-54085Wazuh: Missing input validation in multiple active response scripts allows argument injectionwazuh
CVE-2026-54083Wazuh: Path traversal in ip-customblock active response allows arbitrary file creation and deletionwazuh
CVE-2026-49441Wazuh : peer-controlled metadata key in process_files_from_worker non-merged branch allows arbitrary file write under…wazuh
CVE-2026-49392Wazuh: Local SQL injection in FIM db due to path lookup interpolation in wazuh-syscheckdwazuh
CVE-2026-48162Wazuh: cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file…wazuh
CVE-2026-48024Wazuh: merged-file header path traversal in cluster sync allows arbitrary file write under WAZUH_PATH in Wazuh managerwazuh
CVE-2026-46343Wazuh: Arbitrary File Deletion via Cluster Protocol – Incomplete Path Validation in end_receiving_file()wazuh
CVE-2026-45798Wazuh: Pre-auth stack-buffer-overflow in compare_wazuh_versions reachable from wazuh-authd (TCP/1515) via crafted…wazuh
CVE-2026-44901Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerabilitywazuh
CVE-2026-44253Wazuh: Cluster Protocol Memory Exhaustion (DoS) via unbounded receive_str allocation and div_msg_box accumulationwazuh
CVE-2026-44251Wazuh : size_t underflow in msgs.c ReadSecMSG causes wazuh-remoted DoS and potential heap overflow via crafted agent…wazuh
CVE-2026-41424Wazuh: Privilege Escalation via Admin-Protection Bypass in update-user API Endpointwazuh
CVE-2026-40106Wazuh: Heap-based Buffer Overflow in syscheck Registry Wildcard Expansion (LPE / DoS)wazuh
CVE-2026-33754Wazuh: Unauthenticated cluster packet length leads to uncontrolled memory allocation (remote DoS)wazuh
CVE-2026-30893Wazuh cluster sync path traversal in decompress_files() enables arbitrary file write and code execution from…wazuh
CVE-2026-28221Wazuh: Pre-auth stack-based buffer overflow in wazuh-remoted print_hex_string() due to signed char promotion on x86_64wazuh
CVE-2026-28220Wazuh cluster DAPI arbitrary callable deserialization and RBAC context injection allow a cluster peer to execute…wazuh
CVE-2026-26206Wazuh: API brute-force protection bypass via race condition in login attempt trackingwazuh
CVE-2026-25790Wazuh has Stack-Based Buffer Overflow in Security Configuration Assessment JSON Parserwazuh
CVE-2026-25772Wazuh Database Synchronization Vulnerable to Stack-based Buffer Overflow via snprintf Integer Underflowwazuh
CVE-2026-25771Wazuh Vulnerable to Denial of Service via Synchronous I/O Blocking in Asynchronous Authentication Middlewarewazuh
CVE-2025-64483Wazuh API – Agent Configuration Has Improper Access Control in Agent Enrollment Endpointwazuh-dashboard-plugins
CVE-2025-62786Wazuh Vulnerable to Heap-based Buffer Out-Of-Bounds WRITE in decode_win_permissionswazuh
CVE-2025-15616Wazuh Agent and Manager OS Command Injection and Untrusted Search Pathwazuh-agent; wazuh-manager
CVE-2025-15615Wazuh Manager authd service Improper SSL/TLS Renegotiation Handling leading to Denial of Servicewazuh-manager
CVE-2025-15612Wazuh Provisioning Scripts / Build Infrastructure Improper Certificate Validation leading to MITM and RCEWazuh Provisioning Scripts (Agent Build Environment)
CVE-2024-32038Wazuh Analysis Engine Event Decoder Heap-based Buffer Overflow Remote Code Execution Vulnerabilitywazuh
CVE-2024-1243Remote code execution and local privilege escalation in Wazuh Windows agent via NetNTLMv2 hash theftWazuh Agent
71 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.