Executive brief
Wazuh is an open-source security platform used for monitoring and protecting IT infrastructure. A vulnerability in the manager component allows a connected agent to send a specially crafted message that causes the central management service to crash. This results in a denial-of-service, preventing the platform from processing security data and monitoring the environment until the service is restarted.
Technical details
A NULL pointer dereference exists in the wazuh-modulesd component of Wazuh Manager within the inventory_sync module. The vulnerability is located in the handling of FlatBuffer DataValue messages where the 'id' field is defined as optional in the schema but treated as mandatory by the consumer logic. An authenticated/enrolled agent can transmit a verifier-valid message that omits the 'id' field, leading the manager to call string_view() on a null pointer. This results in a SIGSEGV crash of the wazuh-modulesd process. The issue is addressed in version 5.0.0-beta3 by adding proper null validation before dereferencing the field.
Affected products
- Wazuh Wazuh Manager < 5.0.0-beta3
Timeline
- 2026-05-30: other: Vulnerability discovered and tested in lab environment.
- 2026-06-08: advisory: GHSA-6hxp-c9x3-qc7p published.
- 2026-07-08: disclosed: CVE-2026-56401 published.