Junglewise Threat Intelligence

CVE-2026-48162: Wazuh path traversal in cluster DAPI send_tmp_file

CVE-2026-48162 · Severity: critical · CVSS 9.1 · Published 2026-08-19

Technologies: Wazuh. Vendors: Wazuh.

Executive brief

Wazuh is an open-source security operations platform that monitors and responds to threats across infrastructure. A flaw in its cluster communication protocol allows a peer node holding the shared encryption key to read arbitrary files from the master server, including the private API authentication key. An attacker can abuse this to forge administrator tokens and gain full administrative control over the platform without creating a user account.

Technical details

The vulnerability is a path traversal flaw in the DistributedAPI.send_tmp_file() method (framework/wazuh/core/cluster/dapi/dapi.py). The method fails to canonicalize or confine an attacker-controlled tmp_file parameter before joining it to WAZUH_PATH, allowing traversal sequences (../) or absolute paths to escape the intended directory. An authenticated cluster peer (one holding the shared Fernet key) can exploit this to read any file accessible to the Wazuh process, notably /var/ossec/api/configuration/security/private_key.pem. With the private key, an attacker can cryptographically forge REST API authentication tokens for administrator accounts offline, bypassing account creation and authentication mechanisms. The fix adds realpath() canonicalization and validates that resolved paths remain within OSSEC_TMP_PATH. Affected versions: 4.0.0–4.14.5 and 5.0.0-beta2; patched in 4.14.6 and 5.0.0-beta3.

Affected products

  • Wazuh Wazuh 4.0.0 to 4.14.5, 5.0.0-beta2

Timeline

  • 2026-08-19: disclosed
  • 2026-05-21: patched: Fixed in versions 4.14.6 and 5.0.0-beta3

References

Related threats