NDJSON Injection Vulnerability in Wazuh Manager by Wazuh
CVE-2026-56699

10CRITICAL

Key Information:

Vendor

Wazuh

Status
Vendor
CVE Published:
15 July 2026

What is CVE-2026-56699?

The vulnerability in Wazuh Manager prior to version 5.0.0-beta3 allows for NDJSON injection via the DataValue.index field. This flaw enables attackers to craft malicious payloads, which can be embedded in bulk requests sent to OpenSearch. When executed, these unauthorized commands can lead to critical issues such as document deletion, alteration of alerts, and manipulation of SIEM states across agents. Organizations using this product are urged to adopt immediate mitigations to prevent exploitation.

Affected Version(s)

wazuh 5.0.0-beta1 < 5.0.0-beta3

wazuh 5.0.0-beta3

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

TarPeg007
juliancnn
.