๐Ÿ” CVE Alert

CVE-2026-67307

MEDIUM 6.3

Wazuh before 5.0.0-beta3 Cluster Attribution Spoofing via Inventory Sync

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_node fields in inventory-sync Start FlatBuffer messages, while validating only the agentid against the authenticated agent identity. This allows a low-privileged enrolled agent to spoof cluster attribution in indexed inventory and vulnerability documents by forging wazuh.cluster.name values and influencing the document _id prefix, potentially tampering with inventory records or, in shared-indexer multi-cluster deployments, poisoning another cluster's records when numeric agent IDs collide.

CWE CWE-345
Vendor wazuh
Product wazuh
Published Aug 1, 2026
Stay Ahead of the Next One

Get instant alerts for wazuh wazuh

Be the first to know when new medium vulnerabilities affecting wazuh wazuh are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
High
Availability
None

Affected Versions

wazuh / wazuh
0 < 5.0.0-beta3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/wazuh/wazuh/security/advisories/GHSA-jv5p-fhwh-9w55 github.com: https://github.com/wazuh/wazuh/commit/b3dae02ec9ddcfd449cb61b4c76d180e3e43f79a vulncheck.com: https://www.vulncheck.com/advisories/wazuh-before-beta3-cluster-attribution-spoofing-via-inventory-sync

Credits

๐Ÿ” nasaa0x