Low-privilege API User Vulnerability in Wazuh Security Platform
CVE-2026-61802
6.5MEDIUM
What is CVE-2026-61802?
In the Wazuh Security Platform, low-privilege API users can access the cleartext cluster key due to a flaw in the configuration endpoint in versions 4.14.0 through 4.14.6. The endpoint, which is supposed to mask sensitive information, fails to do so, allowing unauthorized access to critical security data. This exposure enables low-privileged accounts to potentially exploit the cluster key, which is crucial for authenticating and securing communication between cluster nodes. As a result, this vulnerability sets the stage for further exploitation through remote code execution chains.
Affected Version(s)
wazuh >= 4.14.0, < 4.14.7
