PT-2026-25923 · Wazuh · Wazuh

Skraft9

·

Published

2026-03-17

·

Updated

2026-03-24

·

CVE-2026-25770

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wazuh versions 3.9.0 through 4.14.2
Description Wazuh is a platform used for threat prevention, detection, and response. A privilege escalation issue exists in the Wazuh Manager's cluster synchronization protocol. The wazuh-clusterd service allows authenticated nodes to write arbitrary files to the manager’s file system with the permissions of the wazuh system user. Due to insecure default permissions, the wazuh user has write access to the manager's main configuration file (/var/ossec/etc/ossec.conf). By leveraging the cluster protocol to overwrite ossec.conf, an attacker can inject a malicious <localfile> command block. The wazuh-logcollector service, which runs as root, parses this configuration and executes the injected command. This allows an attacker with cluster credentials to gain full Root Remote Code Execution. The wazuh-clusterd service and the /var/ossec/etc/ossec.conf file are key components in this issue.
Recommendations Wazuh versions 3.9.0 through 4.14.2 should be upgraded to version 4.14.3.

Exploit

Fix

RCE

LPE

Incorrect Permission

Path traversal

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2026-05079
CVE-2026-25770
GHSA-R4F7-V3P6-79JM

Affected Products

Wazuh