Heap Buffer Overflow in Wazuh Analysis Engine Affects Open Source Security Platform
CVE-2026-34150

7.5HIGH

Key Information:

Vendor

Wazuh

Status
Vendor
CVE Published:
16 July 2026

What is CVE-2026-34150?

A heap buffer overflow vulnerability has been identified in the Wazuh analysis engine, impacting versions 1.0.0 up to 4.14.4. This flaw enables an unauthenticated remote attacker to crash the analysis engine, leading to a complete halt in Security Information and Event Management (SIEM) alert processing. Exploitation can occur due to the default configuration of the Wazuh Docker deployment, where attackers can easily enroll with authd without a password. By sending specially crafted rootcheck events containing patterns longer than 30 bytes, attackers trigger a buffer overflow in the W_JSON_ParseRootcheck function, corrupting the heap and stopping alert processing while the user interfaces continue to show outdated information. Proper remediation measures should be implemented to safeguard against this vulnerability.

Affected Version(s)

wazuh >= 1.0.0, < 4.14.5

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.