← Back to CVE search

CVE-2026-74038

Wazuh

Description

Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause denial of service by enrolling an agent with a dot-sequence name such as -..- through the enrollment port. Attackers exploit insufficient validation in OS_IsValidName() and unsafe path concatenation in delete_diff() to resolve the traversal to the parent queue directory, causing its subdirectories to be removed and stopping all Wazuh services requiring manual recovery.

CVSS 7.1EPSS 0.35100000000000003%Risk 0.73
View source
Published
2026-08-18 18:19:33
Affected versions
>=4.0.0,<4.14.6
Type
Critical software
Last modified
2026-08-19 16:19:09
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H