File Path Manipulation in Wazuh Affects Security Configurations
CVE-2026-49441
9.1CRITICAL
What is CVE-2026-49441?
The Wazuh platform, renowned for its capabilities in threat prevention and detection, is susceptible to a file path manipulation vulnerability. Specifically, in versions 4.3.0 through 4.14.6 and 5.0.0-beta3, a weakness in the process_files_from_worker() function allows a malicious actor with access to the shared Fernet key to upload a specially crafted file. This could result in overwriting critical configuration files, like ossec.conf, thereby enabling unauthorized command execution upon service reload. Users are advised to upgrade to versions 4.14.6 or 5.0.0-beta3 to mitigate this risk.
Affected Version(s)
wazuh >= 4.3.0, < 4.14.6 < 4.3.0, 4.14.6
wazuh >= 5.0.0-beta1, < 5.0.0-beta3 < 5.0.0-beta1, 5.0.0-beta3
