{"id":"CVE-2026-44252","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-44252","summary":"Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.5, Wazuh Manager allows a low-privilege read-only API user with manager:read…","details":"Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.5, Wazuh Manager allows a low-privilege read-only API user with manager:read permission to retrieve the cluster key from the element in ossec.conf through GET /manager/configuration?raw=true. An attacker with network access to TCP port 1516 can use the disclosed Fernet key to impersonate a cluster worker and submit distributed API requests containing attacker-controlled rbac_permissions with rbac_mode set to black. Because the master trusts the worker-supplied authorization context, the attacker can create users, assign administrator roles, access credentials and API tokens, modify configuration, and execute actions across agents. This issue is fixed in version 4.14.5.","published":"2026-08-19T16:17:10.690","modified":"2026-08-19T16:17:10.690","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/wazuh/wazuh/commit/b3459f5663702aea14e91330a7a6912081fed2eb","label":"wazuh/wazuh@b3459f5"},"references":[{"type":"WEB","url":"https://github.com/wazuh/wazuh/commit/b3459f5663702aea14e91330a7a6912081fed2eb"},{"type":"WEB","url":"https://github.com/wazuh/wazuh/pull/35307"},{"type":"WEB","url":"https://github.com/wazuh/wazuh/releases/tag/v4.14.5"},{"type":"WEB","url":"https://github.com/wazuh/wazuh/releases/tag/v5.0.0-beta3"},{"type":"WEB","url":"https://github.com/wazuh/wazuh/security/advisories/GHSA-34fx-c2xw-xcpg"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-19T16:17:10.690"}}