Integer Underflow Vulnerability in Wazuh Platform
CVE-2026-44251

6.5MEDIUM

Key Information:

Vendor

Wazuh

Status
Vendor
CVE Published:
17 July 2026

What is CVE-2026-44251?

Wazuh, an open source security platform, suffers from an integer underflow vulnerability in version 3.0.0 and later, prior to 4.14.5. This flaw resides in the os_crypto/shared/msgs.c:389 code and enables enrolled Wazuh agents to crash the wazuh-remoted process on the manager. This leads to the immediate disconnection of all agents from the manager. Additionally, this underflow could be exploited via a second code path, potentially resulting in heap memory corruption. The issue has been rectified in version 4.14.5.

Affected Version(s)

wazuh >= 3.0.0, < 4.14.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.