← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 18, 2026 · 18:19via CVEFeed

CVE-2026-74044 - Wazuh 4.0.0 4.14.6 Path Traversal Arbitrary Directory Deletion via Cluster Hello

Brief

CVE ID : CVE-2026-74044

Published : Aug. 18, 2026, 6:19 p. m.

  • 48 minutes ago

Description : Wazuh 4.

  • 0 before 4.
  • 6 contains a path traversal vulnerability that allows authenticated cluster peers to delete arbitrary directory contents by supplying a traversal-shaped node name in the cluster hello payload without validation.

Attackers holding a valid cluster Fernet key can craft a malicious node name and disconnect, triggering the master's peer cleanup routine to remove the contents of arbitrary directories within the Wazuh installation path writable by the wazuh user.

Severity: 7.0

  • HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed