Executive brief
Wazuh is an open-source security platform used for threat detection and incident response. A vulnerability in its authentication service (authd) could allow an attacker to crash the service by sending specifically malformed data. While this impacts the ability of the system to register or authenticate new agents, it is currently rated as having a low impact on overall operations.
Technical details
A heap-based buffer overflow vulnerability exists in the Wazuh authentication daemon (authd), specifically within the os_auth component. The flaw is triggered when the service processes specially crafted input, leading to memory corruption or malformed heap data. An attacker with network access and low-level privileges can exploit this to cause a denial-of-service (DoS) condition by crashing the daemon. Although the NVD entry references CWE-125 (Out-of-bounds Read), the description specifically identifies a heap-buffer overflow. The vulnerability affects versions up to 3.5.0 and version 4.3.10.
Affected products
- Wazuh Wazuh <= 3.5.0, 4.3.10
Timeline
- 2026-03-27: advisory: Initial advisory published by VulnCheck
- 2026-03-27: disclosed: CVE-2026-32984 published to NVD