Junglewise Threat Intelligence

CVE-2026-54083: Wazuh ip-customblock path traversal in active response

CVE-2026-54083 · Severity: high · CVSS 8.1 · Published 2026-08-28

Technologies: Wazuh. Vendors: Wazuh.

Executive brief

Wazuh is an open-source security platform that monitors endpoints and cloud workloads for threats. Its ip-customblock active response script contains a path traversal vulnerability that allows attackers to create or delete arbitrary files on the system with root privileges. An attacker who can generate specially crafted security alerts can exploit this to delete critical system files (like password databases or SSH keys) or create disruptive files, potentially compromising the entire system's security and availability.

Technical details

The vulnerability is a path traversal (CWE-22) in the ip-customblock.c active response script. The script constructs file paths by concatenating the srcip field from alert JSON directly into a fixed /ipblock/ directory without validating the IP address format. An attacker can inject directory traversal sequences (../) in the srcip field to escape the intended directory and reach arbitrary filesystem paths. The active response daemon runs as root, allowing both arbitrary file creation (via append mode in ADD_COMMAND) and deletion (via remove() in DELETE_COMMAND). The fix, available in version 4.14.7, adds IP address validation using get_ip_version() to reject malformed input, matching the pattern already used in sibling scripts like host-deny.c.

Affected products

  • Wazuh Wazuh 4.2.0 to 4.14.6

Timeline

  • 2026-08-28: disclosed
  • 2026-08-18: patched: Version 4.14.7 released with fix

References

Related threats