Description
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.5, Wazuh Manager allows a low-privilege read-only API user with manager:read permission to retrieve the cluster key from the element in ossec.conf through GET /manager/configuration?raw=true. An attacker with network access to TCP port 1516 can use the disclosed Fernet key to impersonate a cluster worker and submit distributed API requests containing attacker-controlled rbac_permissions with rbac_mode set to black. Because the master trusts the worker-supplied authorization context, the attacker can create users, assign administrator roles, access credentials and API tokens, modify configuration, and execute actions across agents. This issue is fixed in version 4.14.5.
Published: 2026-08-19
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Wazuh Manager versions 4.0.0 through 4.14.5 enable a low‑privilege read‑only API user with manager:read permission to fetch the cluster Fernet key from ossec.conf via GET /manager/configuration?raw=true. An attacker who can reach TCP port 1516 can reuse this key to masquerade as a cluster worker, sending distributed API requests that contain attacker‑controlled rbac_permissions and rbac_mode set to black. Because the Manager accepts the worker‑supplied authorization context, the attacker can create and manage users, assign administrator roles, access credentials and API tokens, modify configuration, and launch actions on all agents, effectively taking full administrative control of the deployment. The issue is fixed in version 4.14.5.

Affected Systems

The vulnerability affects the Wazuh Manager component of the Wazuh platform, specifically releases 4.0.0 through 4.14.5. Deployments of these versions that expose TCP 1516 to an external network are vulnerable. The fix is available from version 4.14.5 onward.

Risk and Exploitability

The CVSS score of 7.7 indicates high severity. The EPSS score is <1%, indicating a very low but nonzero likelihood of exploitation, and the CVE is not listed in the CISA KEV catalog. However, the attack vector is straightforward: an attacker with network reach to TCP 1516 and a low‑privilege manager:read user can retrieve the cluster key and perform privileged operations without additional discovery, allowing full control over the Wazuh deployment.

Generated by OpenCVE AI on August 20, 2026 at 14:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Wazuh Manager update to version 4.14.5 or later to eliminate the privilege escalation path.
  • Restrict external access to TCP 1516 with firewall rules or network segmentation, allowing only trusted hosts.
  • Remove manager:read permission from low‑privilege API users or enforce stricter RBAC policies to prevent cluster key disclosure.
  • Monitor Wazuh logs for unauthorized cluster key usage or creation of administrative users.

Generated by OpenCVE AI on August 20, 2026 at 14:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Wazuh
Wazuh wazuh
Vendors & Products Wazuh
Wazuh wazuh

Wed, 19 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.5, Wazuh Manager allows a low-privilege read-only API user with manager:read permission to retrieve the cluster key from the element in ossec.conf through GET /manager/configuration?raw=true. An attacker with network access to TCP port 1516 can use the disclosed Fernet key to impersonate a cluster worker and submit distributed API requests containing attacker-controlled rbac_permissions with rbac_mode set to black. Because the master trusts the worker-supplied authorization context, the attacker can create users, assign administrator roles, access credentials and API tokens, modify configuration, and execute actions across agents. This issue is fixed in version 4.14.5.
Title Wazuh Manager dapi RBAC Bypass Allows Privilege Escalation
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-21T19:38:50.521Z

Reserved: 2026-05-05T16:33:55.844Z

Link: CVE-2026-44252

cve-icon Vulnrichment

Updated: 2026-08-21T19:38:44.300Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T16:17:10.690

Modified: 2026-09-09T21:19:49.197

Link: CVE-2026-44252

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T15:00:05Z

Weaknesses