Junglewise Threat Intelligence

CVE-2026-34150: Wazuh Manager heap buffer overflow in wazuh-analysisd

CVE-2026-34150 · Severity: high · CVSS 7.5 · Published 2026-07-17

Technologies: Wazuh Manager. Vendors: Wazuh.

Executive brief

Wazuh is an open-source security platform used by organizations to monitor for threats and manage security alerts. A vulnerability in the system's analysis engine allows an unauthenticated attacker to remotely crash the service, effectively blinding the security team to new threats. While the management dashboard may appear functional, it will only display old data, and no new security alerts will be processed until the system is patched and restarted.

Technical details

A heap-based buffer overflow exists in the 'W_JSON_ParseRootcheck' function within 'wazuh-analysisd'. The vulnerability is triggered when the engine parses rootcheck events containing JSON-like '{key: value}' patterns. The code allocates a fixed 30-byte buffer but uses 'sprintf' to write unbounded regex matches into it, leading to heap corruption. In default configurations (specifically the official Docker deployment), unauthenticated agent enrollment is enabled, allowing an attacker to obtain valid encryption keys via 'authd' and subsequently inject malicious events via 'remoted'. An exploit results in the silent termination of the analysis engine while the API and dashboard remain active, displaying stale data. The issue is resolved in version 4.14.5.

Affected products

  • Wazuh Wazuh Manager >= 1.0.0, < 4.14.5

Timeline

  • 2026-07-16: advisory: GitHub Security Advisory GHSA-rvr9-89q8-w883 published
  • 2026-07-17: disclosed: CVE-2026-34150 published to NVD
  • 2026-07-16: patched: Fix released in version 4.14.5

References

Related threats