Impact
The vulnerability exists because Wazuh Manager does not escape the DataValue.index field when constructing OpenSearch bulk requests for inventory synchronization. As a result, agents that are allowed to send inventory data can inject arbitrary NDJSON operations such as delete, index, or update. This allows an attacker to delete documents, tamper alerts, and manipulate the SIEM state using the manager’s administrative credentials, compromising the integrity of the system’s data.
Affected Systems
The affected product is Wazuh Wazuh. Any installation of Wazuh Manager before version 5.0.0‑beta3 is vulnerable. No specific device or platform variants are listed beyond the generic product and version requirement.
Risk and Exploitability
The CVSS score of 10 categorizes this vulnerability as critical, and the EPSS score of less than 1 % indicates a low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers require the ability to enroll or control an agent that communicates with the manager, making the likely attack vector agent‑controlled data injection over the network. Exploitability is therefore limited to environments where an attacker can influence agent input or where agents are compromised.
OpenCVE Enrichment