W

Wazuh Security Vulnerabilities (CVE)

Explore vulnerabilities and security advisories affecting Wazuh products.

5 known CVE vulnerabilities tracked

Critical
1
High
0
Medium
4
Low
0
None
0

Vulnerabilities By Year

Products Affected

All Wazuh CVEs

CVE-2026-41499
6.5 medium

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to before version 4.14.4, multiple heap-based out-of-bounds WRITE vulnerabilities exist in parse_uname_string() (remoted_op.c). This function processes OS identification data from agents

Wazuh Apr 29, 2026
CVE-2026-30893
9.0 critical

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to before version 4.14.4, a path traversal vulnerability in Wazuh's cluster synchronization extraction routine allows an authenticated cluster peer to write arbitrary files outside the in

Wazuh Apr 29, 2026
CVE-2026-28221
6.5 medium

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.8.0 to before version 4.14.4, a stack-based buffer overflow exists in print_hex_string() in wazuh-remoted. The bug is triggered when formatting attacker-controlled bytes using sprintf(dst_buf

Wazuh Apr 29, 2026
CVE-2026-26206
6.5 medium

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to before version 4.14.4, Wazuh's server API brute-force protection for POST /security/user/authenticate can be bypassed by sending concurrent authentication requests. Although the config

Wazuh Apr 29, 2026
CVE-2026-26204
4.4 medium

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 1.0.0 to before version 4.14.4, a heap-based out-of-bounds WRITE occurs in GetAlertData, resulting in writing a NULL byte exactly 1 byte before the start of the buffer allocated by strdup. Due

Wazuh Apr 29, 2026