Path Traversal Vulnerability in Wazuh by Wazuh
CVE-2026-74044
7HIGH
What is CVE-2026-74044?
Wazuh versions prior to 4.14.6 exhibit a path traversal vulnerability that enables authenticated cluster peers to manipulate directory contents. By sending a specially crafted node name through the cluster hello payload, attackers with valid cluster Fernet keys can engage in a malicious act. This can result in the inadvertent removal of files and directories within the Wazuh installation that are writable by the wazuh user. The vulnerability poses a significant risk by potentially allowing unauthorized deletion of critical files, thus affecting system integrity.
Affected Version(s)
wazuh-manager 4.0.0 < 4.14.6
