Command Injection Flaw in Wazuh Security Platform
CVE-2026-54085

7.1HIGH

Key Information:

Vendor

Wazuh

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-54085?

Wazuh, an open-source security platform, is susceptible to a command injection vulnerability due to the inability of several active response scripts to validate attacker-controlled input. In versions 4.2.0 to 4.14.6, critical script vulnerabilities permit attackers to execute unvalidated commands as root. Specifically, scripts handling alert fields like srcip can be manipulated to execute unauthorized firewall and account-management commands. This flaw allows adversaries to lock system accounts and potentially run arbitrary commands on affected systems. Users are urged to upgrade to version 4.14.7 or later to mitigate risks associated with this vulnerability.

Affected Version(s)

wazuh >= 4.2.0, < 4.14.7

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.