Junglewise Threat Intelligence

CVE-2021-26814: Wazuh API code injection via /manager/files

CVE-2021-26814 · Severity: low · CVSS 3.1 · Published 2021-03-18

Technologies: Wazuh. Vendors: Wazuh.

Executive brief

Wazuh is a security monitoring and threat detection platform used by organizations to protect their IT infrastructure. An authenticated user can exploit incomplete input validation in the API's file management endpoint to inject and execute arbitrary code with administrative privileges, compromising the entire monitoring system and its protected assets.

Technical details

The vulnerability is an improper input validation flaw (CWE-20) in the Wazuh API's /manager/files and /cluster/{node_id}/files endpoints. An authenticated attacker can exploit incomplete validation to inject arbitrary code that executes within the API service process. The attack requires valid API credentials and network access to the API endpoint. Successful exploitation allows remote code execution with administrative privileges, enabling complete system compromise. The vulnerability affects versions 4.0.0 through 4.0.3 and was fixed in version 4.0.4.

Affected products

  • Wazuh Wazuh 4.0.0 to 4.0.3

Timeline

  • 2021-03-06: disclosed: NVD publication date
  • 2021-03-18: advisory: GitHub advisory GHSA-w36g-q975-37rg published
  • 2021-03-18: patched: Fix released in version 4.0.4

References

Related threats