vciy

CVEs we hold for Wazuh

Records whose assigning authority named Wazuh as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-74046Wazuh 4.4.0 < 4.14.7 DoS via fdecompress_files() Zip Bombwazuh-manager
CVE-2026-74044Wazuh 4.0.0 < 4.14.6 Path Traversal Arbitrary Directory Deletion via Cluster Hellowazuh-manager
CVE-2026-74039Wazuh 4.0.0 < 4.14.7 API DoS via Deeply Nested JSON auth_contextwazuh-manager
CVE-2026-74038Wazuh 4.0.0 < 4.14.6 Path Traversal DoS via Agent Enrollmentwazuh-manager
CVE-2026-67308Wazuh GitHub Actions Shell Injection via Fork Pull Requestwazuh
CVE-2026-67307Wazuh before 5.0.0-beta3 Cluster Attribution Spoofing via Inventory Syncwazuh
CVE-2026-61802Wazuh discloses cleartext cluster key to low-privilege API users via GET /cluster/local/configwazuh
CVE-2026-61800Wazuh cluster worker file sync allows arbitrary file write under /var/ossec (incomplete fix for CVE-2026-30893)wazuh
CVE-2026-61783Wazuh: RBAC permission-effect check in mask_sensitive_config allows low-privilege users to read cluster.keywazuh
CVE-2026-54085Wazuh: Missing input validation in multiple active response scripts allows argument injectionwazuh
CVE-2026-54084Wazuh agent enrollment NULL pointer dereference via malformed manager responsewazuh
CVE-2026-54083Wazuh: Path traversal in ip-customblock active response allows arbitrary file creation and deletionwazuh
CVE-2026-49441Wazuh : peer-controlled metadata key in process_files_from_worker non-merged branch allows arbitrary file write under…wazuh
CVE-2026-49392Wazuh: Local SQL injection in FIM db due to path lookup interpolation in wazuh-syscheckdwazuh
CVE-2026-48162Wazuh: cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file…wazuh
CVE-2026-48024Wazuh: merged-file header path traversal in cluster sync allows arbitrary file write under WAZUH_PATH in Wazuh managerwazuh
CVE-2026-46343Wazuh: Arbitrary File Deletion via Cluster Protocol – Incomplete Path Validation in end_receiving_file()wazuh
CVE-2026-45798Wazuh: Pre-auth stack-buffer-overflow in compare_wazuh_versions reachable from wazuh-authd (TCP/1515) via crafted…wazuh
CVE-2026-44901Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerabilitywazuh
CVE-2026-44256Wazuh: CRLF Log Injection via Unsanitized Basic-Auth Usernamewazuh
CVE-2026-44255Wazuh: Username Enumeration via Timing Side-Channelwazuh
CVE-2026-44254Wazuh: Stack Out-of-Bounds Write in remoted Decompression Pathwazuh
CVE-2026-44253Wazuh: Cluster Protocol Memory Exhaustion (DoS) via unbounded receive_str allocation and div_msg_box accumulationwazuh
CVE-2026-44252Wazuh Manager dapi RBAC Bypass Allows Privilege Escalationwazuh
CVE-2026-44251Wazuh : size_t underflow in msgs.c ReadSecMSG causes wazuh-remoted DoS and potential heap overflow via crafted agent…wazuh
CVE-2026-41499Wazuh: Multiple Heap-based NULL WRITE Buffer Underflows in parse_uname_string()wazuh
CVE-2026-41424Wazuh: Privilege Escalation via Admin-Protection Bypass in update-user API Endpointwazuh
CVE-2026-40106Wazuh: Heap-based Buffer Overflow in syscheck Registry Wildcard Expansion (LPE / DoS)wazuh
CVE-2026-39359Wazuh: Unauthenticated Path Traversal in authd via Agent Group Namewazuh
CVE-2026-34150Wazuh: Heap buffer overflow in wazuh-analysisd via rootcheck event parsingwazuh
CVE-2026-33754Wazuh: Unauthenticated cluster packet length leads to uncontrolled memory allocation (remote DoS)wazuh
CVE-2026-33434Wazuh: Rate Limit Bypass via /events Endpointwazuh
CVE-2026-32984Heap buffer overflow in wazuh-authdWazuh
CVE-2026-32983SSL/TLS Renegotiation DoS in Wazuh Manager authd servicewazuh-manager
CVE-2026-30893Wazuh cluster sync path traversal in decompress_files() enables arbitrary file write and code execution from…wazuh
CVE-2026-28221Wazuh: Pre-auth stack-based buffer overflow in wazuh-remoted print_hex_string() due to signed char promotion on x86_64wazuh
CVE-2026-28220Wazuh cluster DAPI arbitrary callable deserialization and RBAC context injection allow a cluster peer to execute…wazuh
CVE-2026-26206Wazuh: API brute-force protection bypass via race condition in login attempt trackingwazuh
CVE-2026-26204Wazuh: Heap-based NULL WRITE Buffer Underflow in GetAlertDatawazuh
CVE-2026-25790Wazuh has Stack-Based Buffer Overflow in Security Configuration Assessment JSON Parserwazuh
CVE-2026-25772Wazuh Database Synchronization Vulnerable to Stack-based Buffer Overflow via snprintf Integer Underflowwazuh
CVE-2026-25771Wazuh Vulnerable to Denial of Service via Synchronous I/O Blocking in Asynchronous Authentication Middlewarewazuh
CVE-2026-25770Wazuh has Privilege Escalation to Root via Cluster Protocol File Writewazuh
CVE-2026-25769Wazuh Cluster vulnerable to Remote Code Execution via Insecure Deserializationwazuh
CVE-2025-64483Wazuh API – Agent Configuration Has Improper Access Control in Agent Enrollment Endpointwazuh-dashboard-plugins
CVE-2025-64169Wazuh NULL pointer dereference in fim_alert line 666wazuh
CVE-2025-62792Wazuh vulnerable to Heap-based Buffer Over-read in w_expression_matchwazuh
CVE-2025-62791Wazuh vulnerable to NULL pointer dereference in DecodeCiscatwazuh
CVE-2025-62790Wazuh vulnerable to NULL pointer dereference in fim_fetch_attributes_statewazuh
CVE-2025-62789Wazuh vulnerable to NULL pointer dereference in fim_alert line 712wazuh
CVE-2025-62788Wazuh Vulnerable to Heap Use After Free in w_copy_event_for_logwazuh
CVE-2025-62787Wazuh Vulnerable to Heap-based Buffer Over-read in DecodeWinevtwazuh
CVE-2025-62786Wazuh Vulnerable to Heap-based Buffer Out-Of-Bounds WRITE in decode_win_permissionswazuh
CVE-2025-62785Wazuh fillData NULL pointer dereference causes analysisd crashwazuh
CVE-2025-59938Heap buffer overflow in wazuh-analysisdwazuh
CVE-2025-54866Wazuh installation fails to protected authd.pass on Windowswazuh
CVE-2025-30201Wazuh NetNTLMv2 Hash Theft In Multiple Centralized Configuration Capabilitieswazuh
CVE-2025-24016Remote code execution in Wazuh serverwazuh
CVE-2025-15617Wazuh GitHub Actions Workflow Exposure of Sensitive CredentialsWazuh (GitHub Actions)
CVE-2025-15616Wazuh Agent and Manager OS Command Injection and Untrusted Search Pathwazuh-agent; wazuh-manager
CVE-2025-15615Wazuh Manager authd service Improper SSL/TLS Renegotiation Handling leading to Denial of Servicewazuh-manager
CVE-2025-15612Wazuh Provisioning Scripts / Build Infrastructure Improper Certificate Validation leading to MITM and RCEWazuh Provisioning Scripts (Agent Build Environment)
CVE-2024-47770Ability to view Agent list with no privilege access in wazuh-dashboardwazuh
CVE-2024-35177Improper Access Control in wazuh-agentwazuh
CVE-2024-32038Wazuh Analysis Engine Event Decoder Heap-based Buffer Overflow Remote Code Execution Vulnerabilitywazuh
CVE-2024-1243Remote code execution and local privilege escalation in Wazuh Windows agent via NetNTLMv2 hash theftWazuh Agent
CVE-2023-7340Wazuh authd service (os_auth) Heap-based Buffer OverflowWazuh
CVE-2023-50260Wazuh's vulnerability in host_deny AR script allows arbitrary command executionwazuh
CVE-2023-49275Wazuh vulnerable to NULL Pointer Dereference in wazuh-analysisdwazuh
CVE-2023-42463wazuh-logcollector integer underflow local privilege escalationwazuh
CVE-2023-42455Wazuh vulnerable to user privilege escalationwazuh-kibana-app

71 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.