Impact
Wazuh’s cluster handling routine WazuhCommon.end_receiving_file() permits a cluster‑authenticated node to delete arbitrary files when it processes a syn_i_w_m_e request with an unknown task_id. The routine builds a file path from the attacker‑controlled filename without normalizing or confining it, so absolute paths and traversal sequences can remove sensitive configuration files such as ossec.conf, jwt_secret.json, TLS certificates, and ruleset files. Removing these items can cause the Wazuh manager to stop, invalidate API tokens, and break cluster and API connectivity, effectively disabling key security services.
Affected Systems
The vulnerability affects the open‑source Wazuh platform, specifically deployments using Wazuh 4.0.0 through 4.14.5 and pre‑5.0.0‑beta2 releases. Security patches are included in Wazuh version 4.14.6 and newer, as well as in the 5.0.0‑beta2 release.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. EPSS score of 0.00264 indicates a very low probability of exploitation, but the deletion of critical system files remains a significant risk, especially in environments with cluster nodes that can authenticate. The vulnerability is not listed in the CISA KEV catalog, but the potential for a denial‑of‑service and integrity breach warrants aggressive remediation.
OpenCVE Enrichment