Impact
Wazuh 4.0.0 through 4.14.6 and 5.0.0-beta2 expose a denial‑of‑service flaw that targets authenticated users with the allow_run_as flag enabled. By submitting POST requests to the /security/user/authenticate/run_as endpoint containing auth_context bodies with arbitrarily deep JSON nesting, an attacker can force the API framework to consume excessive CPU resources, draining processing capacity and denying service to other API clients.
Affected Systems
The vulnerability affects Wazuh Manager releases prior to version 4.14.7, including older 4.x series and the 5.0.0‑beta2 branch. Only installations running these impacted versions are at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity flaw. EPSS data is not available, and the vulnerability is not listed in CISA KEV. Exploitation requires authentication with allow_run_as enabled, suggesting that the threat surfaces primarily in environments where privileged run‑as functionality is enabled or misconfigured. An attacker could repeatedly trigger the vulnerability to exhaust CPU, effectively denying service to legitimate users.
OpenCVE Enrichment