Admin Access Vulnerability in Wazuh Threat Detection Platform
CVE-2026-41424
8.2HIGH
What is CVE-2026-41424?
A critical authorization bypass vulnerability exists in the Wazuh platform, where authenticated users with 'users_admin' role can reset passwords for protected administrator accounts, including the superuser. The vulnerability arises from a faulty API endpoint that fails to accurately validate the identity of the user making the request. This allows a malicious actor who has gained limited access to the system to escalate their privileges, undermining the integrity of the administrative controls within Wazuh. The issue has been resolved in Wazuh versions 4.10.4 and 4.14.6, making it imperative for users to upgrade to these patched versions.
Affected Version(s)
wazuh >=4.9.0, < 4.10.4 < 4.9.0, 4.10.4
wazuh >= 4.11.0, < 4.14.6 < 4.11.0, 4.14.6
