Path Traversal Vulnerability in Wazuh Product by Wazuh
CVE-2026-74038
7HIGH
What is CVE-2026-74038?
Wazuh versions prior to 4.14.6 are affected by a path traversal vulnerability that enables unauthenticated remote attackers to initiate denial of service. By enrolling an agent with a dot-sequence name (e.g., '..'), attackers can exploit inadequate validation methods in OS_IsValidName() and improper path concatenation in delete_diff(). This allows them to resolve the traversal to the parent queue directory, ultimately leading to the deletion of subdirectories and necessitating manual recovery of all affected Wazuh services.
Affected Version(s)
wazuh-manager 4.0.0 < 4.14.6
