Heap Buffer Overflow in Wazuh Analysis Engine Affects Open Source Security Platform
CVE-2026-34150
What is CVE-2026-34150?
A heap buffer overflow vulnerability has been identified in the Wazuh analysis engine, impacting versions 1.0.0 up to 4.14.4. This flaw enables an unauthenticated remote attacker to crash the analysis engine, leading to a complete halt in Security Information and Event Management (SIEM) alert processing. Exploitation can occur due to the default configuration of the Wazuh Docker deployment, where attackers can easily enroll with authd without a password. By sending specially crafted rootcheck events containing patterns longer than 30 bytes, attackers trigger a buffer overflow in the W_JSON_ParseRootcheck function, corrupting the heap and stopping alert processing while the user interfaces continue to show outdated information. Proper remediation measures should be implemented to safeguard against this vulnerability.
Affected Version(s)
wazuh >= 1.0.0, < 4.14.5
