CVE-2026-56699

Source
https://cve.org/CVERecord?id=CVE-2026-56699
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-56699.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-56699
Aliases
  • GHSA-ff9g-85jq-r3g3
Published
2026-07-15T11:25:32Z
Modified
2026-08-07T11:49:31Z
Severity
  • 10.0 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVSS Calculator
Summary
Wazuh Manager - NDJSON Injection in inventory_sync via Agent-Controlled DataValue.index
Details

Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON operations. Attackers can smuggle delete, index, or update operations into bulk requests executed under the manager's admin credentials, enabling document deletion, alert tampering, and cross-agent SIEM state manipulation.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-74"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56699.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "5.0.0-beta1"
                },
                {
                    "fixed": "5.0.0-beta3"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "introduced": "5.0.0-beta1"
                },
                {
                    "fixed": "5.0.0-beta3"
                }
            ],
            "source": "CPE_FIELD"
        },
        {
            "extracted_events": [
                {
                    "fixed": "5.0.0-beta3"
                }
            ],
            "source": "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/wazuh/wazuh

Affected ranges

Type
GIT
Repo
https://github.com/wazuh/wazuh
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "5.0.0-beta3"
        }
    ],
    "source": "DESCRIPTION"
}

Affected versions

Other
issue-34476-fim-tests
v2.*
v2.0
v3.*
v3.1.0
v3.12.0
v3.13.0
v3.13.1
v3.2.0
v3.5.0
v3.6.0
v3.6.1
v3.7.0
v3.8.0
v5.*
v5.0.0-alpha0
v5.0.0-beta1
v5.0.0-beta2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-56699.json"