CVE-2026-74044Medium· 6.5▾ SunlitWazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster peers to delete arbitrary directory contents by supplying a traversal-shaped node name in the cluster hello payload without validation. A…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
Last analysed / modified upstream
0.4% → 0.4%
Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster peers to delete arbitrary directory contents by supplying a traversal-shaped node name in the cluster hello payload without validation. Attackers holding a valid cluster Fernet key can craft a malicious node name and disconnect, triggering the master's peer cleanup routine to remove the contents of arbitrary directories within the Wazuh installation path writable by the wazuh user.
wazuh >= 4.0.0, < 4.14.6Upgrade past the affected range:
wazuh 4.14.6Connected by shared product, vendor, weakness, or advisory.
CVE-2026-48024Critical· 9.1Wazuh is a free and open source platform used for threat prevention, detection, and response
CVE-2026-46343High· 7.2Wazuh is a free and open source platform used for threat prevention, detection, and response
CVE-2026-61800Critical· 9.1Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads
CVE-2026-54083High· 8.1Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads
CVE-2026-74038High· 7.1Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause denial of service by enrolling an agent with a dot-sequence name such as ".." through the enrollment port
CVE-2026-44256Medium· 5.3Wazuh is a free and open source platform used for threat prevention, detection, and response