CVE-2026-25769

Source
https://cve.org/CVERecord?id=CVE-2026-25769
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25769.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-25769
Aliases
  • GHSA-3gm7-962f-fxw5
Published
2026-03-17T17:41:08.640Z
Modified
2026-04-10T05:40:46.629640Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Wazuh Cluster vulnerable to Remote Code Execution via Insecure Deserialization
Details

Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.14.2 have a Remote Code Execution (RCE) vulnerability due to Deserialization of Untrusted Data). All Wazuh deployments using cluster mode (master/worker architecture) and any organization with a compromised worker node (e.g., through initial access, insider threat, or supply chain attack) are impacted. An attacker who gains access to a worker node (through any means) can achieve full RCE on the master node with root privileges. Version 4.14.3 fixes the issue.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25769.json",
    "cwe_ids": [
        "CWE-502"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/wazuh/wazuh

Affected ranges

Type
GIT
Repo
https://github.com/wazuh/wazuh
Events

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25769.json"