Impact
A low‑privileged agent enrolled in a Wazuh cluster can forge the cluster_name and cluster_node fields in inventory‑sync Start FlatBuffer messages. The system only checks the agentid against the authenticated identity, so an attacker can spoof cluster attribution. This vulnerability allows an attacker to alter indexed inventory and vulnerability documents, potentially corrupting inventory records for their own cluster or poisoning another cluster’s records when numeric agent IDs collide. The weakness is a form of improper input validation, specifically CWE‑345.
Affected Systems
The issue affects Wazuh deployments running before version 5.0.0‑beta3. Versions 5.0.0‑beta1 and 5.0.0‑beta2 are vulnerable. The fix is available in 5.0.0‑beta3 and later releases. The affected product is the Wazuh agent and manager services that participate in cluster inventory synchronization.
Risk and Exploitability
The CVSS base score is 7, indicating a high severity condition. The EPSS score is not provided, so the current exploitation probability is unclear, but the vulnerability is actively used in shared‑indexer multi‑cluster environments and is not reported in the CISA KEV catalog. The likely attack vector is an authenticated agent that can send crafted inventory‑sync messages, underscoring that the threat is exploitable by any user with enrollment rights in the cluster.
OpenCVE Enrichment