Logic Flaw in Wazuh Manager Affects Enrollment and Synchronization Daemons
CVE-2026-39359

7.5HIGH

Key Information:

Vendor

Wazuh

Status
Vendor
CVE Published:
16 July 2026

What is CVE-2026-39359?

Wazuh Manager has a logic flaw affecting its enrollment and synchronization daemons that allows for path traversal. Specifically, the authd process permits agents to select a group for enrollment without adequately filtering path traversal sequences like '../'. This oversight enables an attacker to manipulate directory references, thus potentially gaining access to sensitive configuration files within the /var/ossec/etc directory, including client.keys and ossec.conf. As a result, these sensitive files are exposed during the agent's configuration synchronization process. This vulnerability has been patched in subsequent Wazuh versions 4.10.4 and 4.14.5.

Affected Version(s)

wazuh >= 4.0.0, < 4.10.4 < 4.0.0, 4.10.4

wazuh >= 4.11.0, < 4.14.5 < 4.11.0, 4.14.5

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.