← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 18, 2026 · 18:19via CVEFeed

CVE-2026-74038 - Wazuh 4.0.0 4.14.6 Path Traversal DoS via Agent Enrollment

Brief

CVE ID : CVE-2026-74038

Published : Aug. 18, 2026, 6:19 p. m.

  • 48 minutes ago

Description : Wazuh 4.

  • 0 before 4.
  • 6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause denial of service by enrolling an agent with a dot-sequence name such as ".." through the enrollment port.

Attackers exploit insufficient validation in OS_IsValidName() and unsafe path concatenation in delete_diff() to resolve the traversal to the parent queue directory, causing its subdirectories to be removed and stopping all Wazuh services requiring manual recovery.

Severity: 7.1

  • HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed