Command Injection Flaw in Wazuh Security Platform
CVE-2026-54085
7.1HIGH
What is CVE-2026-54085?
Wazuh, an open-source security platform, is susceptible to a command injection vulnerability due to the inability of several active response scripts to validate attacker-controlled input. In versions 4.2.0 to 4.14.6, critical script vulnerabilities permit attackers to execute unvalidated commands as root. Specifically, scripts handling alert fields like srcip can be manipulated to execute unauthorized firewall and account-management commands. This flaw allows adversaries to lock system accounts and potentially run arbitrary commands on affected systems. Users are urged to upgrade to version 4.14.7 or later to mitigate risks associated with this vulnerability.
Affected Version(s)
wazuh >= 4.2.0, < 4.14.7
