Out-of-Bounds Write Vulnerability in Wazuh Platform
CVE-2026-44254
5.3MEDIUM
What is CVE-2026-44254?
The vulnerability in Wazuh allows for an out-of-bounds write due to improper handling of encrypted agent messages. Specifically, the HandleSecureMessage() function inadvertently passes a pointer to a stack buffer, leading to a situation where compressed agent messages can cause buffer overflow. This results in possible crashes of the remoted daemon, disrupting communication between agents. Versions 4.14.6 and 5.0.0-beta2 address this flaw, ensuring safer message processing and improved stability.
Affected Version(s)
wazuh >= 1.0.0, < 4.14.6 < 1.0.0, 4.14.6
wazuh >= 5.0.0-beta1, < 5.0.0-beta2 < 5.0.0-beta1, 5.0.0-beta2
