Cluster Attribution Spoofing in Wazuh 5.0.0-beta1 by Wazuh
CVE-2026-67307
7HIGH
What is CVE-2026-67307?
Wazuh version 5.0.0-beta1 contains a flaw that permits a low-privileged enrolled agent to manipulate the cluster attribution in inventory and vulnerability documents. This occurs due to inadequate validation of the cluster_name and cluster_node fields in Start FlatBuffer messages during inventory synchronization. As a result, attackers can spoof values associated with wazuh.cluster.name, which compromises the integrity of indexed inventory records. This vulnerability also poses a threat in multi-cluster deployments where numeric agent IDs may inadvertently collide, potentially allowing attackers to poison data across clusters.
Affected Version(s)
wazuh 0 < 5.0.0-beta3
wazuh 5.0.0-beta3
