File Path Manipulation in Wazuh Affects Security Configurations
CVE-2026-49441

9.1CRITICAL

Key Information:

Vendor

Wazuh

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-49441?

The Wazuh platform, renowned for its capabilities in threat prevention and detection, is susceptible to a file path manipulation vulnerability. Specifically, in versions 4.3.0 through 4.14.6 and 5.0.0-beta3, a weakness in the process_files_from_worker() function allows a malicious actor with access to the shared Fernet key to upload a specially crafted file. This could result in overwriting critical configuration files, like ossec.conf, thereby enabling unauthorized command execution upon service reload. Users are advised to upgrade to versions 4.14.6 or 5.0.0-beta3 to mitigate this risk.

Affected Version(s)

wazuh >= 4.3.0, < 4.14.6 < 4.3.0, 4.14.6

wazuh >= 5.0.0-beta1, < 5.0.0-beta3 < 5.0.0-beta1, 5.0.0-beta3

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.