Denial of Service Vulnerability in Wazuh API by Authenticated Attackers
CVE-2026-74039

7.1HIGH

Key Information:

Vendor

Wazuh

Vendor
CVE Published:
18 August 2026

What is CVE-2026-74039?

Authenticated attackers with the 'allow_run_as' feature enabled can exploit a weakness in the Wazuh API. By submitting deeply nested JSON structures to the POST /security/user/authenticate/run_as endpoint, they can compel the API framework to consume disproportionate CPU resources. This activity can disrupt service availability, denying access to legitimate users and causing considerable strain on system resources.

Affected Version(s)

wazuh-manager 4.0.0 < 4.14.7

wazuh-manager 5.0.0-beta2

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

APhuongKMA
jepalfer
.