Denial of Service in Wazuh Open-Source Security Platform
CVE-2026-61811

6.5MEDIUM

Key Information:

Vendor

Wazuh

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-61811?

The Wazuh Security Platform has a vulnerability in its XML processing functionality, specifically in the _getattributes() function. This flaw allows an enrolled agent to submit a Windows EventChannel event containing an excessively deep element with numerous attributes, which can deplete the stack memory allocated for analysisd worker threads. This can lead to a segmentation fault, thereby disrupting the log ingestion process. The vulnerability arises because the function does not limit the number of attributes processed for a single element, which has been corrected in version 4.14.7.

Affected Version(s)

wazuh >= 3.8.0, < 4.14.7

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.