Description
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.4.0 through 4.14.6, a party holding the cluster key can write, overwrite, or delete arbitrary files under /var/ossec on worker nodes, leading to remote code execution as root. During cluster file synchronization, the non-merged branch of update_master_files_in_worker() moves each staged file to a destination derived only from safe_join(), which confines the path to /var/ossec but never verifies that the file lands in the directory declared by its cluster_item_key. Because the destination check present on the primary node and on the worker's merged branch was not applied, a peer can place files at attacker-chosen locations under /var/ossec, including paths that are executed as root, and the delete branch has the same gap. This is an incomplete fix for CVE-2026-30893, which addressed traversal outside /var/ossec but left this path able to redirect files anywhere within it. This issue is fixed in version 4.14.7.
Published: 2026-08-27
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Wazuh’s cluster file synchronization logic removes a critical destination check on worker nodes, allowing any entity that holds the cluster key to write, overwrite, or delete files anywhere under /var/ossec. This arbitrary file write can be leveraged to place malicious binaries or alter system configuration, resulting in root‑level execution. The weakness represents an improper path traversal safeguard (CWE‑22).

Affected Systems

Wazuh, versions 4.4.0 through 4.14.6, on all worker nodes supporting clustering.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.1, denoting a severe impact. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. Attackers need only a valid cluster key and connectivity to a worker node; during replication, the missing check permits the placement of files at arbitrary locations under /var/ossec, enabling code execution as root. The flaw is now fixed in version 4.14.7.

Generated by OpenCVE AI on August 28, 2026 at 07:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Wazuh to version 4.14.7 or later, which implements the missing destination check.
  • Configure the cluster to use a key only on trusted, authorized nodes and audit the cluster configuration to prevent unauthorized peer participation.
  • Isolate or disable cluster file synchronization for worker nodes until the patch is applied, or restrict worker nodes to a trusted intranet segment.

Generated by OpenCVE AI on August 28, 2026 at 07:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Wazuh
Wazuh wazuh
Vendors & Products Wazuh
Wazuh wazuh

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.4.0 through 4.14.6, a party holding the cluster key can write, overwrite, or delete arbitrary files under /var/ossec on worker nodes, leading to remote code execution as root. During cluster file synchronization, the non-merged branch of update_master_files_in_worker() moves each staged file to a destination derived only from safe_join(), which confines the path to /var/ossec but never verifies that the file lands in the directory declared by its cluster_item_key. Because the destination check present on the primary node and on the worker's merged branch was not applied, a peer can place files at attacker-chosen locations under /var/ossec, including paths that are executed as root, and the delete branch has the same gap. This is an incomplete fix for CVE-2026-30893, which addressed traversal outside /var/ossec but left this path able to redirect files anywhere within it. This issue is fixed in version 4.14.7.
Title Wazuh cluster worker file sync allows arbitrary file write under /var/ossec (incomplete fix for CVE-2026-30893)
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-27T23:26:28.110Z

Reserved: 2026-07-10T20:06:05.617Z

Link: CVE-2026-61800

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T02:16:21.767

Modified: 2026-08-28T02:16:21.767

Link: CVE-2026-61800

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T08:00:13Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')