Description
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.5.0 until 4.14.6 and 5.0.0-beta2, compare_wazuh_versions() in src/shared/version_op.c copies the attacker-controlled enrollment V: field into a 10-byte stack buffer with strncpy() but does not explicitly terminate the buffer. The function is reachable before authentication through wazuh-authd on TCP port 1515 when anonymous TLS enrollment is enabled. A version string of at least nine non-null bytes can cause strchr() and strtok() to read beyond ver2 and can make strtok() write a null byte into adjacent stack memory, allowing a remote denial of service. This issue is fixed in versions 4.14.6 and 5.0.0-beta2.
Published: 2026-08-19
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability originates from an unsafe copy of the enrollment V field into a fixed 10‑byte buffer within compare_wazuh_versions(). The code uses strncpy() without ensuring null‑termination, which allows a specially crafted string of at least nine non‑null bytes to overflow the buffer. This overflow can trigger strchr() and strtok() to read beyond the intended boundary, and strtok() may write a null byte into adjacent stack memory, ultimately causing the wazuh‑authd process to crash. The crash results in a denial of service before user authentication is completed.

Affected Systems

This flaw affects Wazuh releases from version 4.5.0 up to, but not including, 4.14.6, and also earlier 5.0.0-beta releases prior to 5.0.0-beta2. Version 4.14.6 and 5.0.0-beta2 contain the fix and are not vulnerable.

Risk and Exploitability

The CVSS score of 7.5 labels the issue as high risk, and the lack of an EPSS rating means the exploitation probability cannot be precisely quantified yet. The flaw is not listed in CISA's KEV catalog, suggesting it has not yet been actively exploited in the wild. Attackers would need to send a crafted enrollment V field to wazuh‑authd over TCP port 1515 while anonymous TLS enrollment is enabled, giving them remote denial of service without requiring authentication.

Generated by OpenCVE AI on August 20, 2026 at 14:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Wazuh to version 4.14.6 or later, which contains the fix for this buffer overflow.
  • If an immediate upgrade is not possible, disable anonymous TLS enrollment in the wazuh‑authd configuration to eliminate the vulnerable input path.
  • Restrict external access to TCP port 1515 or place the Wazuh server on a private network to reduce exposure to potential attackers.

Generated by OpenCVE AI on August 20, 2026 at 14:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Wazuh
Wazuh wazuh
Vendors & Products Wazuh
Wazuh wazuh

Wed, 19 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.5.0 until 4.14.6 and 5.0.0-beta2, compare_wazuh_versions() in src/shared/version_op.c copies the attacker-controlled enrollment V: field into a 10-byte stack buffer with strncpy() but does not explicitly terminate the buffer. The function is reachable before authentication through wazuh-authd on TCP port 1515 when anonymous TLS enrollment is enabled. A version string of at least nine non-null bytes can cause strchr() and strtok() to read beyond ver2 and can make strtok() write a null byte into adjacent stack memory, allowing a remote denial of service. This issue is fixed in versions 4.14.6 and 5.0.0-beta2.
Title Wazuh: Pre-auth stack-buffer-overflow in compare_wazuh_versions reachable from wazuh-authd (TCP/1515) via crafted enrollment V: field
Weaknesses CWE-121
CWE-170
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-19T17:20:26.591Z

Reserved: 2026-05-13T08:19:32.603Z

Link: CVE-2026-45798

cve-icon Vulnrichment

Updated: 2026-08-19T17:19:19.872Z

cve-icon NVD

Status : Received

Published: 2026-08-19T17:18:49.730

Modified: 2026-08-19T18:16:39.973

Link: CVE-2026-45798

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T14:15:05Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow

  • CWE-170

    Improper Null Termination