NDJSON Injection Vulnerability in Wazuh Manager by Wazuh
CVE-2026-56699
10CRITICAL
What is CVE-2026-56699?
The vulnerability in Wazuh Manager prior to version 5.0.0-beta3 allows for NDJSON injection via the DataValue.index field. This flaw enables attackers to craft malicious payloads, which can be embedded in bulk requests sent to OpenSearch. When executed, these unauthorized commands can lead to critical issues such as document deletion, alteration of alerts, and manipulation of SIEM states across agents. Organizations using this product are urged to adopt immediate mitigations to prevent exploitation.
Affected Version(s)
wazuh 5.0.0-beta1 < 5.0.0-beta3
wazuh 5.0.0-beta3
