CVE-2026-54085High· 7.1▾ TwilightWazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.2.0 through 4.14.6, multiple active response scripts pass attacker-influenced alert fields to privileged…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
0.2% → 0.2%
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.2.0 through 4.14.6, multiple active response scripts pass attacker-influenced alert fields to privileged system commands without validating their format, allowing argument injection into tools that run as root. Five of the eight scripts that handle the srcip field, route-null.c, netsh.c, pf.c, npf.c, and ipfw.c, omit the get_ip_version() check that rejects non-IP input, and disable-account.c passes the dstuser field to passwd/chuser with only a comparison against "root". An attacker who can inject crafted log events, for example via syslog, can supply srcip or dstuser values that, when an active response rule triggers, are passed unvalidated to firewall and account-management commands such as pfctl, npfctl, ipfw, route, netsh, and passwd. This enables injecting additional command arguments, and on Windows the unquoted CreateProcess command-line concatenation in wpopenv() lets a srcip containing spaces add further arguments, while disable-account.c can be abused to lock arbitrary system accounts. This issue is fixed in version 4.14.7.
wazuh >= 4.2.0, < 4.14.7Upgrade past the affected range:
wazuh 4.14.7Connected by shared product, vendor, weakness, or advisory.
CVE-2026-44256Medium· 5.3Wazuh is a free and open source platform used for threat prevention, detection, and response
CVE-2026-44253Medium· 4.9Wazuh is a free and open source platform used for threat prevention, detection, and response
CVE-2026-45798High· 7.5Wazuh is a free and open source platform used for threat prevention, detection, and response
CVE-2026-48024Critical· 9.1Wazuh is a free and open source platform used for threat prevention, detection, and response
CVE-2026-48162Critical· 9.1Wazuh is a free and open source platform used for threat prevention, detection, and response
CVE-2026-49392Medium· 5.3Wazuh is a free and open source platform used for threat prevention, detection, and response