๐Ÿ” CVE Alert

CVE-2026-74038

HIGH 7.1

Wazuh 4.0.0 < 4.14.6 Path Traversal DoS via Agent Enrollment

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause denial of service by enrolling an agent with a dot-sequence name such as ".." through the enrollment port. Attackers exploit insufficient validation in OS_IsValidName() and unsafe path concatenation in delete_diff() to resolve the traversal to the parent queue directory, causing its subdirectories to be removed and stopping all Wazuh services requiring manual recovery.

CWE CWE-22
Vendor wazuh
Product wazuh-manager
Published Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for wazuh wazuh-manager

Be the first to know when new high vulnerabilities affecting wazuh wazuh-manager are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
High

Affected Versions

Wazuh / wazuh-manager
4.0.0 < 4.14.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/wazuh/wazuh/security/advisories/GHSA-573w-mqw4-jvmr github.com: https://github.com/wazuh/wazuh/pull/35833 vulncheck.com: https://www.vulncheck.com/advisories/wazuh-path-traversal-dos-via-agent-enrollment

Credits

๐Ÿ” ik0z