Security Flaw in Wazuh Manager Allows Unauthorized Access to Sensitive Configuration
CVE-2026-44252

7.7HIGH

Key Information:

Vendor

Wazuh

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-44252?

A vulnerability in Wazuh Manager, present in versions 4.0.0 to 4.14.5, permits a low-privilege read-only API user with the manager:read permission to extract the cluster key from the configuration file 'ossec.conf.' An attacker gaining network access to TCP port 1516 can exploit this flaw to impersonate a cluster worker. By doing so, they can submit distributed API requests containing malicious role-based access control (RBAC) permissions and achieve unauthorized operations, such as creating users, assigning admin roles, and modifying configurations. This security risk undermines the integrity of the Wazuh environment. The issue has been resolved in version 4.14.5.

Affected Version(s)

wazuh >= 4.0.0, < 4.14.5

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.