PT-2026-25923 · Wazuh · Wazuh

Skraft9

·

Publicado

2026-03-17

·

Atualizado

2026-03-24

·

CVE-2026-25770

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wazuh versions 3.9.0 through 4.14.2
Description Wazuh is a platform used for threat prevention, detection, and response. A privilege escalation issue exists in the Wazuh Manager's cluster synchronization protocol. The wazuh-clusterd service allows authenticated nodes to write arbitrary files to the manager’s file system with the permissions of the wazuh system user. Due to insecure default permissions, the wazuh user has write access to the manager's main configuration file (/var/ossec/etc/ossec.conf). By leveraging the cluster protocol to overwrite ossec.conf, an attacker can inject a malicious <localfile> command block. The wazuh-logcollector service, which runs as root, parses this configuration and executes the injected command. This allows an attacker with cluster credentials to gain full Root Remote Code Execution. The wazuh-clusterd service and the /var/ossec/etc/ossec.conf file are key components in this issue.
Recommendations Wazuh versions 3.9.0 through 4.14.2 should be upgraded to version 4.14.3.

Exploit

Correção

RCE

LPE

Incorrect Permission

Path traversal

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-05079
CVE-2026-25770
GHSA-R4F7-V3P6-79JM

Produtos afetados

Wazuh