Out-of-Bounds Write Vulnerability in Wazuh Platform
CVE-2026-44254

5.3MEDIUM

Key Information:

Vendor

Wazuh

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-44254?

The vulnerability in Wazuh allows for an out-of-bounds write due to improper handling of encrypted agent messages. Specifically, the HandleSecureMessage() function inadvertently passes a pointer to a stack buffer, leading to a situation where compressed agent messages can cause buffer overflow. This results in possible crashes of the remoted daemon, disrupting communication between agents. Versions 4.14.6 and 5.0.0-beta2 address this flaw, ensuring safer message processing and improved stability.

Affected Version(s)

wazuh >= 1.0.0, < 4.14.6 < 1.0.0, 4.14.6

wazuh >= 5.0.0-beta1, < 5.0.0-beta2 < 5.0.0-beta1, 5.0.0-beta2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.