Naar hoofdinhoud

CVE-2026-46343

7.2 HIGHPublieke exploitEPSS 0.33%
  1. Gepubliceerd19 aug 2026

Beschrijving

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, WazuhCommon.end_receiving_file() in framework/wazuh/core/cluster/common.py allows a cluster-authenticated node to delete files outside WAZUH_PATH. A syn_i_w_m_e request with an unknown task_id reaches the cleanup branch, where an attacker-controlled filename is passed to os.path.join without canonicalization or confinement. Absolute paths and traversal sequences can therefore target files such as ossec.conf, jwt_secret.json, TLS certificates, and ruleset files that are accessible to the Wazuh manager process. Deletion can disable the manager, invalidate API tokens, or disrupt cluster and API connectivity. This issue is fixed in versions 4.14.6 and 5.0.0-beta2.

CVSS 3.1-ontleding

Attack vectorNetwork
Attack complexityLow
Privileges requiredHigh
User interactionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Getroffen producten

Wazuh Wazuh≥ 4.0.0 < 4.14.6 · 5.0.0

Veelgestelde vragen

Wordt CVE-2026-46343 actief misbruikt?

CVE-2026-46343 staat niet in de CISA KEV-catalogus. Er bestaat een publieke exploit-referentie, dus behandel het als misbruikbaar. De EPSS-exploitkans is 0.33%.

Hoe ernstig is CVE-2026-46343?

CVE-2026-46343 heeft een CVSS 3.1-basisscore van 7.2, beoordeeld als high. EPSS schat een exploitkans van 0.33%.

Welke producten zijn getroffen door CVE-2026-46343?

Getroffen producten zijn onder meer Wazuh Wazuh.

Hoe verhelp ik CVE-2026-46343?

Werk getroffen software bij naar een opgeloste versie, bijvoorbeeld Wazuh Wazuh 4.14.6 of later, en controleer daarna dat er geen getroffen versies meer in uw inventaris staan.

Hoe Secuno hiermee omgaat

Secuno correleert kwetsbaarheden zoals CVE-2026-46343 dagelijks tegen de werkelijke software-inventaris op elk beheerd apparaat. In plaats van een statische ernst wordt elke match in context gescoord: exploitbeschikbaarheid, EPSS, de blootstelling van het asset en bedrijfskriticiteit bepalen de prioriteit. Als een getroffen versie ergens in uw portfolio aanwezig is, verschijnt die automatisch met een geprioriteerd hersteltraject.

Data uit de NVD, CISA KEV-catalogus en FIRST EPSS. CVSS 3.1-basisscore getoond indien beschikbaar.