Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade the affected package to 4.14.6 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 21 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wazuh
Wazuh wazuh-manager |
|
| Vendors & Products |
Wazuh
Wazuh wazuh-manager |
Fri, 21 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster peers to delete arbitrary directory contents by supplying a traversal-shaped node name in the cluster hello payload without validation. Attackers holding a valid cluster Fernet key can craft a malicious node name and disconnect, triggering the master's peer cleanup routine to remove the contents of arbitrary directories within the Wazuh installation path writable by the wazuh user. | |
| Title | Wazuh 4.0.0 < 4.14.6 Path Traversal Arbitrary Directory Deletion via Cluster Hello | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-20T15:23:54.740Z
Reserved: 2026-08-14T14:06:40.513Z
Link: CVE-2026-74044
Updated: 2026-08-20T13:47:29.784Z
Status : Received
Published: 2026-08-18T18:19:33.907
Modified: 2026-08-20T16:17:59.000
Link: CVE-2026-74044
No data.
OpenCVE Enrichment
Updated: 2026-08-21T21:00:03Z