Executive brief
Wazuh Manager, a central component of the Wazuh security monitoring platform, contains a vulnerability that allows managed agents to bypass security controls. By sending specially crafted data, a compromised or malicious agent can trick the manager into executing unauthorized commands on the backend database. This can lead to the deletion of security alerts, tampering with inventory data for other systems, and the destruction of forensic evidence.
Technical details
An NDJSON injection vulnerability exists in the inventory_sync subsystem of Wazuh Manager. The component fails to escape the 'DataValue.index' field when constructing OpenSearch _bulk requests, allowing an enrolled agent to smuggle arbitrary operations (delete, index, update) into the request stream. Because the manager typically connects to the wazuh-indexer using administrative credentials (all_access role), these smuggled operations execute with full privileges. Attackers can exploit this to delete documents in any wazuh-* index, manipulate SIEM state for other agents, or inject malicious payloads into Kibana saved objects. The vulnerability is present in the 5.0.0-beta1 and beta2 releases and is fixed in 5.0.0-beta3.
Affected products
- Wazuh Wazuh Manager >= 5.0.0-beta1, < 5.0.0-beta3
Timeline
- 2026-06-08: advisory: GitHub Security Advisory published
- 2026-07-15: disclosed: NVD publication date