Metrics
Affected Vendors & Products
No advisories yet.
Solution
Upgrade the affected package to 4.14.6 or later.
Workaround
No workaround given by the vendor.
Fri, 21 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wazuh
Wazuh wazuh-manager |
|
| Vendors & Products |
Wazuh
Wazuh wazuh-manager |
Fri, 21 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster peers to delete arbitrary directory contents by supplying a traversal-shaped node name in the cluster hello payload without validation. Attackers holding a valid cluster Fernet key can craft a malicious node name and disconnect, triggering the master's peer cleanup routine to remove the contents of arbitrary directories within the Wazuh installation path writable by the wazuh user. | |
| Title | Wazuh 4.0.0 < 4.14.6 Path Traversal Arbitrary Directory Deletion via Cluster Hello | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-20T15:23:54.740Z
Reserved: 2026-08-14T14:06:40.513Z
Link: CVE-2026-74044
Updated: 2026-08-20T13:47:29.784Z
Status : Received
Published: 2026-08-18T18:19:33.907
Modified: 2026-08-20T16:17:59.000
Link: CVE-2026-74044
No data.
OpenCVE Enrichment
Updated: 2026-08-21T21:00:03Z