Executive brief
Wazuh is a security platform used for threat detection and response across corporate networks. The authentication system has a timing vulnerability that allows unauthenticated attackers to determine valid usernames by measuring authentication response times. Attackers can exploit this information to refine credential-guessing attacks and gain unauthorized access to the platform.
Technical details
The vulnerability is a timing-based information disclosure flaw in AuthenticationManager.check_user() within framework/wazuh/rbac/orm.py. When an invalid username is supplied, the function returns immediately without performing password validation. When a valid username is supplied, an expensive bcrypt hash calculation is performed, causing a measurable delay. An unauthenticated remote attacker can compare authentication response times to infer whether a username exists in the system. This enables username enumeration attacks that can be chained with credential-guessing techniques. The fix involves performing a dummy bcrypt calculation on all authentication attempts to ensure constant-time operation, regardless of username validity.
Affected products
- Wazuh Wazuh 4.0.0 to 4.14.5, 5.0.0-beta1
Timeline
- 2026-08-19: disclosed
- 2026-04-28: patched: Fix merged in versions 4.14.6 and 5.0.0-beta2