CVE-2026-44252
Last modified
CVE-2026-44252 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.5, Wazuh Manager allows a low-privilege read-only API user with manager:read permission to retrieve the cluster key from the element in ossec.conf through GET /manager/configuration?raw=true. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.5, Wazuh Manager allows a low-privilege read-only API user with manager:read permission to retrieve the cluster key from the element in ossec.conf through GET /manager/configuration?raw=true. An attacker with network access to TCP port 1516 can use the disclosed Fernet key to impersonate a cluster worker and submit distributed API requests containing attacker-controlled rbac_permissions with rbac_mode set to black. Because the master trusts the worker-supplied authorization context, the attacker can create users, assign administrator roles, access credentials and API tokens, modify configuration, and execute actions across agents. This issue is fixed in version 4.14.5.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wazuh | Wazuh | >= 4.0.0, < 4.14.5 |
References
- https://github.com/wazuh/wazuh/pull/35307Issue Tracking, Patch
- https://github.com/wazuh/wazuh/releases/tag/v4.14.5Patch, Release Notes
- https://github.com/wazuh/wazuh/releases/tag/v5.0.0-beta3Patch, Release Notes
- https://github.com/wazuh/wazuh/security/advisories/GHSA-34fx-c2xw-xcpgExploit, Vendor Advisory
- https://github.com/wazuh/wazuh/security/advisories/GHSA-34fx-c2xw-xcpgExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-44252?
How severe is CVE-2026-44252?
How do I fix CVE-2026-44252?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-44247Volcano is a Kubernetes-native batch scheduling system. Prio…7.4
- CVE-2026-44248Netty is an asynchronous, event-driven network application f…7.5
- CVE-2026-44249Netty is a network application framework for development of …8.1
- CVE-2026-4425Rejected reason: Reserved for EastLink case, but no need for…
- CVE-2026-44250Netty is a network application framework for development of …7.5
- CVE-2026-44251Wazuh is a free and open source platform used for threat pre…6.5
- CVE-2026-44253Wazuh is a free and open source platform used for threat pre…4.9
- CVE-2026-44254Wazuh is a free and open source platform used for threat pre…5.3
- CVE-2026-44255Wazuh is a free and open source platform used for threat pre…5.3
- CVE-2026-44256Wazuh is a free and open source platform used for threat pre…5.3
- CVE-2026-44257efw4.X is an Enterprise Framework for Web. Prior to 4.08.010…9.3
- CVE-2026-44258efw4.X is an Enterprise Framework for Web. Prior to 4.08.010…9.3
Are you affected by CVE-2026-44252?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
