Logic Flaw in Wazuh Manager Affects Enrollment and Synchronization Daemons
CVE-2026-39359
7.5HIGH
What is CVE-2026-39359?
Wazuh Manager has a logic flaw affecting its enrollment and synchronization daemons that allows for path traversal. Specifically, the authd process permits agents to select a group for enrollment without adequately filtering path traversal sequences like '../'. This oversight enables an attacker to manipulate directory references, thus potentially gaining access to sensitive configuration files within the /var/ossec/etc directory, including client.keys and ossec.conf. As a result, these sensitive files are exposed during the agent's configuration synchronization process. This vulnerability has been patched in subsequent Wazuh versions 4.10.4 and 4.14.5.
Affected Version(s)
wazuh >= 4.0.0, < 4.10.4 < 4.0.0, 4.10.4
wazuh >= 4.11.0, < 4.14.5 < 4.11.0, 4.14.5
