Memory Allocation Issue in Wazuh Open-Source Security Platform
CVE-2026-71540

7.5HIGH

Key Information:

Vendor

Wazuh

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-71540?

A memory allocation vulnerability exists in the Wazuh security platform affecting versions 3.9.0 to 4.14.7. The issue arises in the wazuh-clusterd component, where an unauthenticated network peer can define a payload buffer size using a 20-byte cluster protocol header. This allows malicious actors to allocate large memory segments of up to 256 MiB without proper validation, leading to potential memory exhaustion. The cluster listener fails to impose limitations on concurrent connections, which can escalate memory consumption and ultimately disrupt the cluster process, impacting synchronization and distributed API services. The vulnerability has been addressed in version 4.14.7.

Affected Version(s)

wazuh >= 3.9.0, < 4.14.7

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.