Vendor
Wazuh Cluster Mode Insecure Deserialization Vulnerability (CVE-2026-25769)
1 CVEAn insecure deserialization vulnerability in Wazuh cluster communication allows a compromised worker node to achieve remote code execution as root on the master node.
Path Traversal Vulnerability in Wazuh Agent Enrollment
1 CVEA path traversal vulnerability in Wazuh versions 4.0.0 through 4.14.5 allows unauthenticated remote attackers to trigger a denial of service by sending a specially crafted agent enrollment request.
Wazuh GitHub Actions Shell Injection Vulnerability
3 TTPs 1 CVEA shell injection vulnerability in Wazuh workflows allows unauthenticated attackers to execute arbitrary commands and exfiltrate secrets via malicious pull requests containing crafted VERSION.json files.
Wazuh Manager Vulnerability CVE-2026-56699 Allows NDJSON Injection
2 TTPs 1 CVEWazuh Manager versions prior to 5.0.0-beta3 are critically vulnerable to an injection flaw, CVE-2026-56699 (CWE-74), enabling enrolled agents to inject arbitrary NDJSON operations into OpenSearch bulk requests, leading to data integrity compromise and defense evasion.
Wazuh Denial of Service Vulnerability
1 TTPA vulnerability in Wazuh allows a remote, authenticated attacker to perform a denial of service attack, which could disrupt the availability of the Wazuh platform.
Multiple Vulnerabilities in Wazuh Allow for Code Execution and Data Manipulation
2 rules 6 TTPs 5 CVEsMultiple vulnerabilities in Wazuh allow an attacker to perform a denial of service attack, execute arbitrary code, manipulate data, disclose confidential information, or bypass security measures.