---
id: CVE-2026-44255
title: >-
  Wazuh is a free and open source platform used for threat prevention,
  detection, and response
summary: >-
  Wazuh is a free and open source platform used for threat prevention,
  detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2,
  AuthenticationManager.check_user() in framework/wazuh/rbac/orm.py performs
  check_password_hash() only …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-208
vendor: wazuh
product: wazuh
affected:
  - 'wazuh >= 4.0.0, < 4.14.6'
  - wazuh = 5.0.0
patched:
  - wazuh 4.14.6
published: '2026-08-19'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T14:52:15.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-44255'
references:
  - url: >-
      https://github.com/wazuh/wazuh/commit/5ecea7b38b998407cb0d205467dd247140a0f981
    label: security-advisories@github.com
  - url: 'https://github.com/wazuh/wazuh/pull/35757'
    label: security-advisories@github.com
  - url: 'https://github.com/wazuh/wazuh/releases/tag/v4.14.6'
    label: security-advisories@github.com
  - url: 'https://github.com/wazuh/wazuh/releases/tag/v5.0.0-beta2'
    label: security-advisories@github.com
  - url: 'https://github.com/wazuh/wazuh/security/advisories/GHSA-3978-44q9-9px9'
    label: security-advisories@github.com
  - url: 'https://github.com/wazuh/wazuh/security/advisories/GHSA-3978-44q9-9px9'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00616
epssPercentile: 0.4724
ingestedAt: '2026-09-09T21:22:45.540Z'
---

## Overview

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, AuthenticationManager.check_user() in framework/wazuh/rbac/orm.py performs check_password_hash() only when the supplied username exists. A nonexistent username returns immediately, while a valid username causes an expensive bcrypt calculation. An unauthenticated remote attacker can compare authentication response times to enumerate valid Wazuh usernames and use that information in subsequent credential attacks. This issue is fixed in versions 4.14.6 and 5.0.0-beta2.

## Affected

- `wazuh >= 4.0.0, < 4.14.6`
- `wazuh = 5.0.0`

## Remediation

Upgrade past the affected range:

- `wazuh 4.14.6`
