New MCP server — Bring vulnerability intelligence into your AI
Back to feed

CVE-2026-39359

ExploitedNVDCIRCL

Published Jul 17, 2026 · Jul 17, 2026

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through 4.10.3 and 4.11.0 through 4.14.4, a logic flaw affects the Wazuh Manager's enrollment daemon (authd) and synchronization daemon (remoted). The authd process allows agents to select a group during enrollment but does not filter path traversal sequences such as "..." While the manager checks for the group directory using wopendir(), the ".." sequence references the parent directory (/var/ossec/etc), allowing it to pass validation. After the malicious group is accepted and stored in the manager's global database, the remoted process uses this unchecked value to build paths for agent configuration synchronization. As a result, sensitive files from /var/ossec/etc, such as client.keys, ossec.conf, and internal certificates, are included in the agent's shared configuration stream and exposed to the attacker. This issue has been fixed in versions 4.10.4 and 4.14.5.

Technologies

Wazuh Wazuh

Weaknesses

CWE-22

CVSS scores

  • v3.17.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References

Potentially impacted assets

See if this affects your attack surface

Latest trending attack

Criticaltoday

WSO2 API Manager - Authentication Bypass via JWT Signature Flaw

WSO2 API Manager is an open-source platform designed for creating, publishing, managing, and monitoring APIs throughout their entire lifecycle, enabling organizations to secure and scale their digital services efficiently. CVE-2026-5430 Critical authentication bypass vulnerability exists in WSO2 API Manager due to an improper signature verification flaw during JSON Web Token (JWT) validation. The system fails to correctly validate the signing algorithm of incoming tokens, allowing it to accept tokens that use unexpected or unsupported cryptographic algorithms. A remote, unauthenticated attacker can exploit this weakness by crafting malicious, self-signed JWTs, thereby bypassing authentication mechanisms and gaining unauthorized access to protected API resources or management consoles with administrative privileges.

Take 15 minutes to discover our platform with our experts

PatrowlIntel platform screenshot