Denial of Service Vulnerability in Wazuh by The Wazuh Team
CVE-2026-74046

6.9MEDIUM

Key Information:

Vendor

Wazuh

Vendor
CVE Published:
18 August 2026

What is CVE-2026-74046?

The vulnerability in Wazuh occurs in the fdecompress_files() function within cluster.py, allowing authenticated cluster peers to exploit memory management. By crafting a malicious synchronization archive with no decompressed size limits, attackers can utilize a zip bomb to saturate memory resources on the master node. With access to a valid cluster Fernet key, they can trigger significant service disruptions as the system attempts to process the oversized payload. This poses risks to server availability and stability in environments relying on Wazuh for security compliance.

Affected Version(s)

wazuh-manager 4.4.0 < 4.14.7

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

moltenbit
jotacarma90
.