← Back to CVE List
Vulnerability Intelligence Report
Wazuh : peer-controlled metadata key in process_files_from_worker non-merged branch allows arbitrary file write under WAZUH_PATH on Wazuh manager

CVE-2026-49441

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.3.0 until 4.14.6 and 5.0.0-beta3, the non-merged branch of process_files_from_worker() in framework/wazuh/core/cluster/master.py trusts a peer-controlled file_path key from files_metadata.json. The destination is joined to WAZUH_PATH without proving that it remains inside the directory selected by cluster_item_key. A cluster peer holding the shared Fernet key can upload a crafted extra-valid archive and overwrite security-sensitive files such as /var/ossec/etc/ossec.conf. Replacing ossec.conf can configure root-executed commands and lead to code execution after a service reload. This issue is fixed in versions 4.14.6 and 5.0.0-beta3.

No Active Exploit Signals
CVSS Base Score
9.1
CRITICAL
Exploitability:2.3
Impact Score:6.1
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-73 ↗CWE-73: External Control of File Name or Path

Affected Products & Versions

Vendor Product Affected Versions
wazuh wazuh >= 4.3.0, < 4.14.6 (affected), >= 5.0.0-beta1, < 5.0.0-beta3 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2026-05-30T02:43:33
Published2026-08-19T16:19:37
Last Updated2026-08-19T18:18:21

LINK COPIED TO CLIPBOARD