Junglewise Threat Intelligence

CVE-2026-44255: Wazuh username enumeration via authentication timing attack

CVE-2026-44255 · Severity: medium · CVSS 5.3 · Published 2026-08-19

Technologies: Wazuh. Vendors: Wazuh.

Executive brief

Wazuh is a security platform used for threat detection and response across corporate networks. The authentication system has a timing vulnerability that allows unauthenticated attackers to determine valid usernames by measuring authentication response times. Attackers can exploit this information to refine credential-guessing attacks and gain unauthorized access to the platform.

Technical details

The vulnerability is a timing-based information disclosure flaw in AuthenticationManager.check_user() within framework/wazuh/rbac/orm.py. When an invalid username is supplied, the function returns immediately without performing password validation. When a valid username is supplied, an expensive bcrypt hash calculation is performed, causing a measurable delay. An unauthenticated remote attacker can compare authentication response times to infer whether a username exists in the system. This enables username enumeration attacks that can be chained with credential-guessing techniques. The fix involves performing a dummy bcrypt calculation on all authentication attempts to ensure constant-time operation, regardless of username validity.

Affected products

  • Wazuh Wazuh 4.0.0 to 4.14.5, 5.0.0-beta1

Timeline

  • 2026-08-19: disclosed
  • 2026-04-28: patched: Fix merged in versions 4.14.6 and 5.0.0-beta2

References

Related threats