Wazuh · Wazuh · CVE-2026-25770
**Name of the Vulnerable Software and Affected Versions**
Wazuh versions 3.9.0 through 4.14.2
**Description**
Wazuh is a platform used for threat prevention, detection, and response. A privilege escalation issue exists in the Wazuh Manager's cluster synchronization protocol. The `wazuh-clusterd` service allows authenticated nodes to write arbitrary files to the manager’s file system with the permissions of the `wazuh` system user. Due to insecure default permissions, the `wazuh` user has write access to the manager's main configuration file (`/var/ossec/etc/ossec.conf`). By leveraging the cluster protocol to overwrite `ossec.conf`, an attacker can inject a malicious `<localfile>` command block. The `wazuh-logcollector` service, which runs as root, parses this configuration and executes the injected command. This allows an attacker with cluster credentials to gain full Root Remote Code Execution. The `wazuh-clusterd` service and the `/var/ossec/etc/ossec.conf` file are key components in this issue.
**Recommendations**
Wazuh versions 3.9.0 through 4.14.2 should be upgraded to version 4.14.3.