Junglewise Threat Intelligence

CVE-2026-41424: Wazuh authentication bypass in user password update

CVE-2026-41424 · Severity: high · CVSS 8.2 · Published 2026-08-19

Technologies: Wazuh. Vendors: Wazuh.

Executive brief

Wazuh is an open-source security platform used to detect and respond to threats across IT environments. An authenticated attacker with administrative privileges can bypass protections on critical system accounts and reset the password of the Wazuh superuser, gaining complete control over the security platform and all monitored systems. This could allow an attacker to disable security monitoring, extract sensitive data, or manipulate security alerts.

Technical details

The vulnerability is an authentication bypass in the PUT /security/users/{user_id} endpoint (api/api/controllers/security_controller.py). The endpoint incorrectly passes request.get("user") instead of the authenticated user's token (request.context['token_info']['sub']) to the authorization logic. The remove_nones_to_dict() function then strips out the resulting None value, preventing the reserved-account protection in framework/wazuh/security.py from validating who initiated the request. An authenticated user with the users_admin role can exploit this to overwrite passwords of protected administrator accounts (user IDs ≤99), including the Wazuh superuser account. The vulnerability affects versions 4.9.0 through 4.10.3 and 4.14.0 through 4.14.5; patches are available in versions 4.10.4 and 4.14.6.

Affected products

  • Wazuh Wazuh 4.9.0 to 4.10.3, 4.14.0 to 4.14.5

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Fixed in versions 4.10.4 and 4.14.6

References

Related threats