Shell Injection Vulnerability in Wazuh Workflows by Wazuh
CVE-2026-67308

5.3MEDIUM

Key Information:

Vendor

Wazuh

Status
Vendor
CVE Published:
1 August 2026

What is CVE-2026-67308?

Wazuh workflows prior to version 44bf114 are susceptible to a shell injection vulnerability found in GitHub Actions. This vulnerability enables attackers to inject malicious commands by submitting pull requests that include specially crafted VERSION.json files. The exploitation occurs when shell metacharacters are inserted into environment variables, which are subsequently interpolated into run steps. Successful exploitation can lead to the execution of arbitrary commands and the potential exfiltration of sensitive data, including GITHUB_TOKEN and AWS credentials, particularly on self-hosted runners. Organizations using affected versions should take immediate corrective actions to mitigate this threat.

Affected Version(s)

wazuh 0 < 44bf114

wazuh 44bf114

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

cybermukesh
Miguevrgo
.