This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
No vendor fix or workaround currently provided.
OpenCVE Recommended Actions
- Upgrade Wazuh to version 5.0.0-beta3 or later to include the null-check fix.
- If a full upgrade is not possible immediately, apply the patch from the commit referenced (3adf4f87942705aa0ceeba1e145c259cc9dcd242) to the wazuh-modulesd source and rebuild.
- Restrict or monitor agent communications to prevent unauthorized malformed inventory_sync messages, and consider disabling inventory_sync for untrusted agents until a functional update is applied.
Generated by OpenCVE AI on July 15, 2026 at 06:57 UTC.
Tracking
Sign in to view the affected projects.
No advisories yet.
No reference.
Wed, 15 Jul 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Wazuh - NULL Pointer Dereference in inventory_sync DataValue FlatBuffer Handling | |
| References |
|
|
| Metrics |
ssvc
|
Wed, 15 Jul 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wazuh wazuh-modulesd before 5.0.0-beta3 contains a null pointer dereference vulnerability in inventory_sync FlatBuffer DataValue handling. An enrolled agent can send a verifier-valid DataValue message omitting the optional id field, causing wazuh-modulesd to crash when dereferencing data->id()->string_view() without null validation, resulting in denial of service. | This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| Weaknesses | CWE-476 | |
| CPEs | ||
| References |
|
|
| Metrics |
cvssV3_1
|
Wed, 08 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 08 Jul 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wazuh wazuh-modulesd before 5.0.0-beta3 contains a null pointer dereference vulnerability in inventory_sync FlatBuffer DataValue handling. An enrolled agent can send a verifier-valid DataValue message omitting the optional id field, causing wazuh-modulesd to crash when dereferencing data->id()->string_view() without null validation, resulting in denial of service. | |
| Title | Wazuh - NULL Pointer Dereference in inventory_sync DataValue FlatBuffer Handling | |
| First Time appeared |
Wazuh
Wazuh wazuh |
|
| Weaknesses | CWE-476 | |
| CPEs | cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wazuh
Wazuh wazuh |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: REJECTED
Assigner: VulnCheck
Published:
Updated: 2026-07-15T11:42:41.971Z
Reserved: 2026-06-21T12:37:58.435Z
Link: CVE-2026-56401
Updated:
Status : Rejected
Published: 2026-07-08T14:17:17.167
Modified: 2026-07-15T12:18:03.157
Link: CVE-2026-56401
No data.
OpenCVE Enrichment
Updated: 2026-07-15T07:00:04Z
No weakness.