File Deletion Vulnerability in Wazuh Platform Affecting Security Processes
CVE-2026-46343
What is CVE-2026-46343?
An issue in the Wazuh platform permits an authenticated cluster node to execute a file deletion attack. By manipulating the WazuhCommon.end_receiving_file() method, an attacker can craft requests that delete crucial configuration files stored outside the designated WAZUH_PATH. This vulnerability allows for the possible removal of essential files such as ossec.conf or TLS certificates, leading to significant disruptions in the Wazuh manager's functionality and potentially compromising the security operations of the system. Users are advised to upgrade to the latest versions, 4.14.6 and 5.0.0-beta2, to mitigate the risk associated with this vulnerability.
Affected Version(s)
wazuh >= 4.0.0, < 4.14.6 < 4.0.0, 4.14.6
wazuh >= 5.0.0-beta1, < 5.0.0-beta2 < 5.0.0-beta1, 5.0.0-beta2
