Path Traversal Vulnerability in Wazuh Platform
CVE-2026-48024
9.1CRITICAL
What is CVE-2026-48024?
The Wazuh platform, utilized for threat detection and response, is susceptible to a path traversal vulnerability due to improper path handling. Specifically, in versions 4.0.0 through 4.14.6 and 5.0.0-beta3, the cluster.unmerge_info() function can lead to the construction of paths from user-controlled input, allowing an attacker with access to the shared Fernet key to manipulate paths in the system. By exploiting this vulnerability, an adversary can replace significant configuration files like ossec.conf, potentially enabling malicious commands to execute upon service reload.
Affected Version(s)
wazuh >= 4.0.0, < 4.14.6 < 4.0.0, 4.14.6
wazuh >= 5.0.0-beta1, < 5.0.0-beta3 < 5.0.0-beta1, 5.0.0-beta3
