Path Traversal Vulnerability in Wazuh Platform
CVE-2026-48024

9.1CRITICAL

Key Information:

Vendor

Wazuh

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-48024?

The Wazuh platform, utilized for threat detection and response, is susceptible to a path traversal vulnerability due to improper path handling. Specifically, in versions 4.0.0 through 4.14.6 and 5.0.0-beta3, the cluster.unmerge_info() function can lead to the construction of paths from user-controlled input, allowing an attacker with access to the shared Fernet key to manipulate paths in the system. By exploiting this vulnerability, an adversary can replace significant configuration files like ossec.conf, potentially enabling malicious commands to execute upon service reload.

Affected Version(s)

wazuh >= 4.0.0, < 4.14.6 < 4.0.0, 4.14.6

wazuh >= 5.0.0-beta1, < 5.0.0-beta3 < 5.0.0-beta1, 5.0.0-beta3

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.