This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Per Wazuh's Security Policy, vulnerabilities affecting only non-GA versions are not eligible for a CVE ID.
No vendor fix or workaround currently provided.
OpenCVE Recommended Actions
- Apply the official Wazuh Manager patch to version 5.0.0‑beta3 or later to close the injection flaw.
- Audit any custom inventory_sync configurations or scripts that manipulate DataValue.index and verify that these are properly sanitized or removed.
- Restrict agent-to-manager traffic to trusted networks or enforce strict authentication to limit the opportunity for malicious agent input.
Generated by OpenCVE AI on July 31, 2026 at 04:01 UTC.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 06 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON operations. Attackers can smuggle delete, index, or update operations into bulk requests executed under the manager's admin credentials, enabling document deletion, alert tampering, and cross-agent SIEM state manipulation. | This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Per Wazuh's Security Policy, vulnerabilities affecting only non-GA versions are not eligible for a CVE ID. |
| Weaknesses | CWE-74 | |
| CPEs | ||
| References |
|
|
| Metrics |
cvssV3_1
|
Wed, 15 Jul 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Jul 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON operations. Attackers can smuggle delete, index, or update operations into bulk requests executed under the manager's admin credentials, enabling document deletion, alert tampering, and cross-agent SIEM state manipulation. | |
| Title | Wazuh Manager - NDJSON Injection in inventory_sync via Agent-Controlled DataValue.index | |
| First Time appeared |
Wazuh
Wazuh wazuh |
|
| Weaknesses | CWE-74 | |
| CPEs | cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wazuh
Wazuh wazuh |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: REJECTED
Assigner: VulnCheck
Published:
Updated: 2026-08-06T16:42:35.813Z
Reserved: 2026-06-22T17:09:16.556Z
Link: CVE-2026-56699
Updated: 2026-07-15T12:42:05.172Z
Status : Rejected
Published: 2026-07-15T12:18:15.293
Modified: 2026-08-06T22:17:59.453
Link: CVE-2026-56699
No data.
OpenCVE Enrichment
Updated: 2026-07-31T04:15:04Z
No weakness.