Impact
Wazuh Manager versions 4.0.0 through 4.14.5 enable a low‑privilege read‑only API user with manager:read permission to fetch the cluster Fernet key from ossec.conf via GET /manager/configuration?raw=true. An attacker who can reach TCP port 1516 can reuse this key to masquerade as a cluster worker, sending distributed API requests that contain attacker‑controlled rbac_permissions and rbac_mode set to black. Because the Manager accepts the worker‑supplied authorization context, the attacker can create and manage users, assign administrator roles, access credentials and API tokens, modify configuration, and launch actions on all agents, effectively taking full administrative control of the deployment. The issue is fixed in version 4.14.5.
Affected Systems
The vulnerability affects the Wazuh Manager component of the Wazuh platform, specifically releases 4.0.0 through 4.14.5. Deployments of these versions that expose TCP 1516 to an external network are vulnerable. The fix is available from version 4.14.5 onward.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity. The EPSS score is <1%, indicating a very low but nonzero likelihood of exploitation, and the CVE is not listed in the CISA KEV catalog. However, the attack vector is straightforward: an attacker with network reach to TCP 1516 and a low‑privilege manager:read user can retrieve the cluster key and perform privileged operations without additional discovery, allowing full control over the Wazuh deployment.
OpenCVE Enrichment