Impact
Wazuh's non‑merged process_files_from_worker() branch allows a cluster peer that controls the file_path key in files_metadata.json to specify any file path. The system concatenates this path with WAZUH_PATH without validating containment, enabling overwriting critical files such as /var/ossec/etc/ossec.conf. Such overwrite can insert malicious root‑executed commands and trigger code execution when the Wazuh service reloads, leading to full system compromise.
Affected Systems
The vulnerability affects Wazuh version 4.3.0 through 4.14.6 and the beta 5.0.0‑beta3 release. Any deployment using the non‑merged process_files_from_worker() branch with a cluster peer sharing the Fernet key is at risk.
Risk and Exploitability
The CVSS score of 9.1 reflects a high‑severity threat. Although the EPSS score is not available, the reliance on a shared Fernet key by a cluster peer provides an authenticated attack vector that can be abused to write arbitrary files. The vulnerability is not yet listed in the CISA KEV catalog, but its potential for code execution warrants immediate attention.
OpenCVE Enrichment