Path Traversal Vulnerability in Wazuh Product by Wazuh
CVE-2026-74038

7HIGH

Key Information:

Vendor

Wazuh

Vendor
CVE Published:
18 August 2026

What is CVE-2026-74038?

Wazuh versions prior to 4.14.6 are affected by a path traversal vulnerability that enables unauthenticated remote attackers to initiate denial of service. By enrolling an agent with a dot-sequence name (e.g., '..'), attackers can exploit inadequate validation methods in OS_IsValidName() and improper path concatenation in delete_diff(). This allows them to resolve the traversal to the parent queue directory, ultimately leading to the deletion of subdirectories and necessitating manual recovery of all affected Wazuh services.

Affected Version(s)

wazuh-manager 4.0.0 < 4.14.6

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ik0z
.