CVE-2026-74038High· 7.1▾ TwilightWazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause denial of service by enrolling an agent with a dot-sequence name such as ".." through the enrollment port. Attackers …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
Last analysed / modified upstream
0.4% → 0.5%
Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause denial of service by enrolling an agent with a dot-sequence name such as ".." through the enrollment port. Attackers exploit insufficient validation in OS_IsValidName() and unsafe path concatenation in delete_diff() to resolve the traversal to the parent queue directory, causing its subdirectories to be removed and stopping all Wazuh services requiring manual recovery.
wazuh >= 4.0.0, < 4.14.6Upgrade past the affected range:
wazuh 4.14.6Connected by shared product, vendor, weakness, or advisory.
CVE-2026-48024Critical· 9.1Wazuh is a free and open source platform used for threat prevention, detection, and response
CVE-2026-46343High· 7.2Wazuh is a free and open source platform used for threat prevention, detection, and response
CVE-2026-61800Critical· 9.1Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads
CVE-2026-54083High· 8.1Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads
CVE-2026-74044Medium· 6.5Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster peers to delete arbitrary directory contents by supplying a traversal-shaped node name in the cluster hello payload without validation
CVE-2026-44256Medium· 5.3Wazuh is a free and open source platform used for threat prevention, detection, and response