Shell Injection Vulnerability in Wazuh Workflows by Wazuh
CVE-2026-67308
5.3MEDIUM
What is CVE-2026-67308?
Wazuh workflows prior to version 44bf114 are susceptible to a shell injection vulnerability found in GitHub Actions. This vulnerability enables attackers to inject malicious commands by submitting pull requests that include specially crafted VERSION.json files. The exploitation occurs when shell metacharacters are inserted into environment variables, which are subsequently interpolated into run steps. Successful exploitation can lead to the execution of arbitrary commands and the potential exfiltration of sensitive data, including GITHUB_TOKEN and AWS credentials, particularly on self-hosted runners. Organizations using affected versions should take immediate corrective actions to mitigate this threat.
Affected Version(s)
wazuh 0 < 44bf114
wazuh 44bf114
