Missing ACL Vulnerability in Wazuh Agent Exposing Passwords
CVE-2025-54866
What is CVE-2025-54866?
The Wazuh Agent, which is a key component of the open-source security platform for threat detection and response, suffers from a vulnerability due to a missing Access Control List on the file located at 'C:\Program Files (x86)\ossec-agent\authd.pass'. This flaw allows any authenticated user on the local machine to gain unauthorized access to sensitive authentication credentials. This vulnerability has been addressed with patches released in version 4.13.0 of the Wazuh Agent, which implements appropriate ACL settings to secure password information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
wazuh >= 4.3.0, < 4.13.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
