Low-privilege API User Vulnerability in Wazuh Security Platform
CVE-2026-61802

6.5MEDIUM

Key Information:

Vendor

Wazuh

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-61802?

In the Wazuh Security Platform, low-privilege API users can access the cleartext cluster key due to a flaw in the configuration endpoint in versions 4.14.0 through 4.14.6. The endpoint, which is supposed to mask sensitive information, fails to do so, allowing unauthorized access to critical security data. This exposure enables low-privileged accounts to potentially exploit the cluster key, which is crucial for authenticating and securing communication between cluster nodes. As a result, this vulnerability sets the stage for further exploitation through remote code execution chains.

Affected Version(s)

wazuh >= 4.14.0, < 4.14.7

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.