{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awazuhwazuh/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-25769"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Wazuh (\u003c 4.14.3)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","wazuh"],"_cs_type":"advisory","_cs_vendors":["Wazuh"],"content_html":"\u003cp\u003eCVE-2026-25769 is a critical insecure deserialization vulnerability affecting the cluster communication mechanism in Wazuh versions prior to 4.14.3. The flaw resides in how the Wazuh master node processes serialized data received from worker nodes within the cluster architecture. If an attacker successfully compromises a single worker node, they can leverage this vulnerability to send maliciously crafted serialized objects to the master node. Upon deserialization, these objects facilitate arbitrary command execution with root privileges on the master node. Given the high CVSS score of 9.1, this vulnerability poses a severe risk to the integrity of the entire security monitoring infrastructure, as a compromise of a worker node leads to a full takeover of the central management server.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full system compromise of the Wazuh master node with root-level access. This results in the complete loss of confidentiality, integrity, and availability for the security monitoring platform, potentially enabling attackers to disable detection capabilities, exfiltrate security logs, or pivot further into the internal network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security operations and IT teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Wazuh instances in cluster configurations to version 4.14.3 or later immediately to patch CVE-2026-25769.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the Wazuh cluster communication ports strictly to authorized worker nodes using host-based firewalls or network access control lists.\u003c/li\u003e\n\u003cli\u003eAudit existing Wazuh worker nodes for signs of prior compromise, as a compromised worker is the prerequisite for exploiting this vulnerability.\u003c/li\u003e\n\u003cli\u003eReview cluster communication logs for anomalies in traffic patterns or unexpected payload sizes originating from worker nodes.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T19:17:51Z","date_published":"2026-08-28T19:17:51Z","id":"https://feed.craftedsignal.io/briefs/2026-08-wazuh-rce/","summary":"An insecure deserialization vulnerability in Wazuh cluster communication allows a compromised worker node to achieve remote code execution as root on the master node.","title":"Wazuh Cluster Mode Insecure Deserialization Vulnerability (CVE-2026-25769)","url":"https://feed.craftedsignal.io/briefs/2026-08-wazuh-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}