PT-2026-35961 · Wazuh · Wazuh

Marius-Momeu

·

Published

2026-04-29

·

Updated

2026-04-29

·

CVE-2026-26204

CVSS v3.1

4.4

Medium

AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wazuh versions 1.0.0 through 4.14.3
Description A heap-based out-of-bounds WRITE occurs in the GetAlertData() function. This is caused by an unsigned integer underflow and pointer arithmetic wrapping, which results in a NULL byte being written exactly 1 byte before the start of the buffer allocated by strdup, thereby corrupting heap metadata. A malicious actor with a compromised agent can exploit this by injecting a specially crafted alert into the alerts log file monitored by wazuh-logcollector to cause heap corruption or denial of service.
Recommendations Update to version 4.14.4.

Fix

Integer Underflow

Weakness Enumeration

Related Identifiers

CVE-2026-26204

Affected Products

Wazuh