CVE-2026-46343
Last modified
CVE-2026-46343 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, WazuhCommon.end_receiving_file() in framework/wazuh/core/cluster/common.py allows a cluster-authenticated node to delete files outside WAZUH_PATH. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, WazuhCommon.end_receiving_file() in framework/wazuh/core/cluster/common.py allows a cluster-authenticated node to delete files outside WAZUH_PATH. A syn_i_w_m_e request with an unknown task_id reaches the cleanup branch, where an attacker-controlled filename is passed to os.path.join without canonicalization or confinement. Absolute paths and traversal sequences can therefore target files such as ossec.conf, jwt_secret.json, TLS certificates, and ruleset files that are accessible to the Wazuh manager process. Deletion can disable the manager, invalidate API tokens, or disrupt cluster and API connectivity. This issue is fixed in versions 4.14.6 and 5.0.0-beta2.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Wazuh | Wazuh | >= 4.0.0, < 4.14.6 | — |
| Wazuh | Wazuh | 5.0.0 | Beta1 |
References
- https://github.com/wazuh/wazuh/pull/36060Issue Tracking, Patch
- https://github.com/wazuh/wazuh/releases/tag/v4.14.6Patch, Release Notes
- https://github.com/wazuh/wazuh/releases/tag/v5.0.0-beta2Patch, Release Notes
- https://github.com/wazuh/wazuh/security/advisories/GHSA-cqvw-w2rg-327fExploit, Vendor Advisory
- https://github.com/wazuh/wazuh/security/advisories/GHSA-cqvw-w2rg-327fExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-46343?
How severe is CVE-2026-46343?
How do I fix CVE-2026-46343?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-46338PyMdown Extensions is a set of extensions for the Python-Mar…4.3
- CVE-2026-463399Router is an AI router & token saver. From 0.4.30 until 0.4…10
- CVE-2026-4634A flaw was found in Keycloak. An unauthenticated attacker ca…7.5
- CVE-2026-46340Netty is a network application framework for development of …7.5
- CVE-2026-46341The Apify MCP server enables AI agents to extract data from …6.1
- CVE-2026-46342Nuxt is an open-source web development framework for Vue.js.…5.4
- CVE-2026-46344liboqs is a C-language cryptographic library that provides i…5.3
- CVE-2026-46345compliance-trestle is a tooling platform for managing compli…8.4
- CVE-2026-46348Mastodon is a free, open-source social network server based …8.7
- CVE-2026-46349Mastodon is a free, open-source social network server based …5.3
- CVE-2026-4635Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4…5.3
- CVE-2026-46351BigBlueButton is an open-source virtual classroom. Prior to …8.1
Are you affected by CVE-2026-46343?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
