CVE-2026-32984
Heap buffer overflow in wazuh-authd
CVSS Score
3.5
EPSS Score
0.1%
EPSS Percentile
19th
Wazuh authd contains a heap-buffer overflow vulnerability that allows attackers to cause memory corruption and malformed heap data by sending specially crafted input. Attackers can exploit this vulnerability to trigger a denial of service condition, resulting in low availability impact to the authentication daemon.
| CWE | CWE-125 |
| Vendor | wazuh |
| Product | wazuh |
| Published | Mar 27, 2026 |
| Last Updated | Mar 31, 2026 |
Stay Ahead of the Next One
Get instant alerts for wazuh wazuh
Be the first to know when new low vulnerabilities affecting wazuh wazuh are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
Affected Versions
Wazuh / Wazuh
3.5.0 4.3.10
References
Credits
Reported by @vikman90; credited to @stasos24.