CVE-2026-54085
Last modified
CVE-2026-54085 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.2.0 through 4.14.6, multiple active response scripts pass attacker-influenced alert fields to privileged system commands without validating their format, allowing argument injection into tools that run as root. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.2.0 through 4.14.6, multiple active response scripts pass attacker-influenced alert fields to privileged system commands without validating their format, allowing argument injection into tools that run as root. Five of the eight scripts that handle the srcip field, route-null.c, netsh.c, pf.c, npf.c, and ipfw.c, omit the get_ip_version() check that rejects non-IP input, and disable-account.c passes the dstuser field to passwd/chuser with only a comparison against "root". An attacker who can inject crafted log events, for example via syslog, can supply srcip or dstuser values that, when an active response rule triggers, are passed unvalidated to firewall and account-management commands such as pfctl, npfctl, ipfw, route, netsh, and passwd. This enables injecting additional command arguments, and on Windows the unquoted CreateProcess command-line concatenation in wpopenv() lets a srcip containing spaces add further arguments, while disable-account.c can be abused to lock arbitrary system accounts. This issue is fixed in version 4.14.7.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wazuh | Wazuh | >= 4.2.0, < 4.14.7 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-54085?
How severe is CVE-2026-54085?
How do I fix CVE-2026-54085?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5408BT-DHT protocol dissector crash in Wireshark 4.6.0 to 4.6.4 …5.5
- CVE-2026-54080veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.3…6.9
- CVE-2026-54081veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.3…6.9
- CVE-2026-54082veraPDF validation model is an implementation of the veraPDF…6.5
- CVE-2026-54083Wazuh is an open-source security platform providing unified …8.1
- CVE-2026-54084Wazuh is an open-source security platform providing unified …5.3
- CVE-2026-54087EasyAdmin is a fast and modern admin generator for Symfony a…7.6
- CVE-2026-54088File Browser is a file managing interface for uploading, del…9.3
- CVE-2026-54089File Browser is a file managing interface for uploading, del…9.1
- CVE-2026-5409Monero protocol dissector crash in Wireshark 4.6.0 to 4.6.4 …5.5
- CVE-2026-54090File Browser is a file managing interface for uploading, del…8.7
- CVE-2026-54091File Browser is a file managing interface for uploading, del…7.5
Are you affected by CVE-2026-54085?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
