Denial of Service Vulnerability in Wazuh API by Authenticated Attackers
CVE-2026-74039
7.1HIGH
What is CVE-2026-74039?
Authenticated attackers with the 'allow_run_as' feature enabled can exploit a weakness in the Wazuh API. By submitting deeply nested JSON structures to the POST /security/user/authenticate/run_as endpoint, they can compel the API framework to consume disproportionate CPU resources. This activity can disrupt service availability, denying access to legitimate users and causing considerable strain on system resources.
Affected Version(s)
wazuh-manager 4.0.0 < 4.14.7
wazuh-manager 5.0.0-beta2
