CVE-2026-74044 - Wazuh 4.0.0 4.14.6 Path Traversal Arbitrary Directory Deletion via Cluster Hello
Brief
CVE ID : CVE-2026-74044
Published : Aug. 18, 2026, 6:19 p. m.
- 48 minutes ago
Description : Wazuh 4.
- 0 before 4.
- 6 contains a path traversal vulnerability that allows authenticated cluster peers to delete arbitrary directory contents by supplying a traversal-shaped node name in the cluster hello payload without validation.
Attackers holding a valid cluster Fernet key can craft a malicious node name and disconnect, triggering the master's peer cleanup routine to remove the contents of arbitrary directories within the Wazuh installation path writable by the wazuh user.
Severity: 7.0
- HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
