CVE-2026-49392

Source
https://cve.org/CVERecord?id=CVE-2026-49392
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49392.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-49392
Aliases
  • GHSA-9c4x-mrjh-rmw5
Published
2026-08-19T16:22:49Z
Modified
2026-09-17T08:15:53Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
Wazuh: Local SQL injection in FIM db due to path lookup interpolation in wazuh-syscheckd
Details

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.6.0 until 4.14.6 and 5.0.0-beta3, DB::getFile() and DB::searchFile() in src/syscheckd/src/db/src/file.cpp concatenate a monitored file path into SQLite row filters. On non-Windows systems, FIMDBCreator::encodeString() does not escape the value. A local user who can create a filename in a File Integrity Monitoring directory can inject a UNION SELECT expression when wazuh-syscheckd processes or deletes that path. The confirmed primitive manipulates SELECT result sets consumed by the FIM code; stacked statements and remote code execution were not demonstrated. This issue is fixed in versions 4.14.6 and 5.0.0-beta3.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-20",
        "CWE-89"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49392.json"
}
References

Affected packages

Git / github.com/wazuh/wazuh

Affected ranges

Type
GIT
Repo
https://github.com/wazuh/wazuh
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:wazuh:wazuh:5.0.0:beta1:*:*:*:*:*:*",
        "cpe:2.3:a:wazuh:wazuh:5.0.0:beta2:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "4.6.0"
        },
        {
            "fixed": "4.14.6"
        },
        {
            "introduced": "5.0.0-beta1"
        },
        {
            "last_affected": "5.0.0-beta1"
        },
        {
            "introduced": "5.0.0-beta2"
        },
        {
            "last_affected": "5.0.0-beta2"
        }
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

5.*
5.0.0-beta1
5.0.0-beta2
v5.*
v5.0.0-beta1
v5.0.0-beta2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49392.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "85530491972539372495397693201677950226",
                "280303132924306178090309099245206099166",
                "296041106916758287527668040999612101005"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-49392-67ecbeed",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/wazuh/wazuh/commit/8e4e25b971dfb7b15bc492f10f8a350e6b37e70e",
        "target": {
            "file": "src/shared_modules/dbsync/src/dbsync.cpp"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "217426457337170919037342268044952148919",
                "22444597553440132548594909837342356542",
                "284264829298123978117692483064306488123"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-49392-6db95d96",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/wazuh/wazuh/commit/8e4e25b971dfb7b15bc492f10f8a350e6b37e70e",
        "target": {
            "file": "src/shared_modules/dbsync/include/dbsync.hpp"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "103139503563022169601854010566850751487",
                "212983457052274876295336013253393680055",
                "165578534732992799248991078116249856622",
                "126065399237702322909297378423456654829",
                "141684718743660186074166159131402514711",
                "118656543947644696680354861037910307996",
                "158966883555370838167210404556834169541",
                "158250271293498239143580046349071675898",
                "213963593876176721501993905648102980684",
                "31647438826521994873382644420184968990",
                "217356985762507454996548582441942337508",
                "59996223079552816678702558463149013970",
                "10017169685876713283801823567598167762",
                "152944861314884125350745320811420704752",
                "128336075695361528814235131332273329487",
                "272691092942694906822138039960022337537",
                "101950082694030744370807777712641403895",
                "5252560053936604091163198014167609797",
                "166060623552554932444826166961725482041",
                "197228880765104719997415568600226769903",
                "137579677882708393064946200348879891026",
                "84916578274557597188148700371593987626",
                "116693787565228908256252992221510363837",
                "80679176151982488240785892739526038088"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-49392-a2db708b",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/wazuh/wazuh/commit/8e4e25b971dfb7b15bc492f10f8a350e6b37e70e",
        "target": {
            "file": "src/syscheckd/src/db/src/file.cpp"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "67522880257496376504339261679235056751",
                "28871860192583593315492935023942785640",
                "319085396199295177919465323538726159576"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-49392-cbba8f6f",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/wazuh/wazuh/commit/8e4e25b971dfb7b15bc492f10f8a350e6b37e70e",
        "target": {
            "file": "src/shared_modules/dbsync/src/sqlite/sqlite_dbengine.cpp"
        }
    }
]
vanir_signatures_modified
"2026-09-17T08:15:53Z"