๐Ÿ” CVE Alert

CVE-2026-74044

MEDIUM 6.5

Wazuh 4.0.0 < 4.14.6 Path Traversal Arbitrary Directory Deletion via Cluster Hello

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster peers to delete arbitrary directory contents by supplying a traversal-shaped node name in the cluster hello payload without validation. Attackers holding a valid cluster Fernet key can craft a malicious node name and disconnect, triggering the master's peer cleanup routine to remove the contents of arbitrary directories within the Wazuh installation path writable by the wazuh user.

CWE CWE-22
Vendor wazuh
Product wazuh-manager
Published Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for wazuh wazuh-manager

Be the first to know when new medium vulnerabilities affecting wazuh wazuh-manager are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High

Affected Versions

Wazuh / wazuh-manager
4.0.0 < 4.14.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/wazuh/wazuh/security/advisories/GHSA-f34r-fcjf-qx6j github.com: https://github.com/wazuh/wazuh/pull/36460 vulncheck.com: https://www.vulncheck.com/advisories/wazuh-path-traversal-arbitrary-directory-deletion-via-cluster-hello

Credits

๐Ÿ” moltenbit vikman90