๐Ÿ” CVE Alert

CVE-2026-56401

MEDIUM 6.5

Wazuh - NULL Pointer Dereference in inventory_sync DataValue FlatBuffer Handling

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Wazuh wazuh-modulesd before 5.0.0-beta3 contains a null pointer dereference vulnerability in inventory_sync FlatBuffer DataValue handling. An enrolled agent can send a verifier-valid DataValue message omitting the optional id field, causing wazuh-modulesd to crash when dereferencing data->id()->string_view() without null validation, resulting in denial of service.

CWE CWE-476
Vendor wazuh
Product wazuh
Published Jul 8, 2026
Last Updated Jul 8, 2026
Stay Ahead of the Next One

Get instant alerts for wazuh wazuh

Be the first to know when new medium vulnerabilities affecting wazuh wazuh are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

Wazuh / Wazuh
0 < 5.0.0-beta3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/wazuh/wazuh/security/advisories/GHSA-6hxp-c9x3-qc7p github.com: https://github.com/wazuh/wazuh/commit/3adf4f87942705aa0ceeba1e145c259cc9dcd242 vulncheck.com: https://www.vulncheck.com/advisories/wazuh-null-pointer-dereference-in-inventory-sync-datavalue-flatbuffer-handling

Credits

kocaemre vikman90