Vulnerabilities & PatchesEmerging1 src
CVE-2026-74044 - Wazuh 4.0.0 4.14.6 Path Traversal Arbitrary Directory Deletion via Cluster Hello
CVE ID : CVE-2026-74044
Published : Aug. 18, 2026, 6:19 p. m.
• 48 minutes ago
Description : Wazuh 4. 0. 0 before 4. 14. 6 contains a path traversal vulnerability that allows authenticated cluster peers to delete arbitrary directory contents by supplying a traversal-shaped node name in the cluster hello payload without validation.
Attackers holding a valid cluster Fernet key can craft a malicious node name and disconnect, triggering the master's peer cleanup routine to remove the contents of arbitrary directories within the Wazuh installation path writable by the wazuh user.
Severity: 7.0
• HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...