Admin Access Vulnerability in Wazuh Threat Detection Platform
CVE-2026-41424

8.2HIGH

Key Information:

Vendor

Wazuh

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-41424?

A critical authorization bypass vulnerability exists in the Wazuh platform, where authenticated users with 'users_admin' role can reset passwords for protected administrator accounts, including the superuser. The vulnerability arises from a faulty API endpoint that fails to accurately validate the identity of the user making the request. This allows a malicious actor who has gained limited access to the system to escalate their privileges, undermining the integrity of the administrative controls within Wazuh. The issue has been resolved in Wazuh versions 4.10.4 and 4.14.6, making it imperative for users to upgrade to these patched versions.

Affected Version(s)

wazuh >=4.9.0, < 4.10.4 < 4.9.0, 4.10.4

wazuh >= 4.11.0, < 4.14.6 < 4.11.0, 4.14.6

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.