CVE-2026-25770Disclosure(wazuh / wazuh)

LOWCVSS 7.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch wazuh wazuh systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 and prior to version 4.14.3, a privilege escalation vulnerability exists in the Wazuh Manager's cluster synchronization protocol. The `wazuh-clusterd` service allows authenticated nodes to write arbitrary files to the manager’s file system with the permissions of the `wazuh` system user. Due to insecure default permissions, the `wazuh` user has write access to the manager's main configuration file (`/var/ossec/etc/ossec.conf`). By leveraging the cluster protocol to overwrite `ossec.conf`, an attacker can inject a malicious `<localfile>` command block. The `wazuh-logcollector` service, which runs as root, parses this configuration and executes the injected command. This chain allows an attacker with cluster credentials to gain full Root Remote Code Execution, violating the principle of least privilege and bypassing the intended security model. Version 4.14.3 fixes the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-269CWE-732

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wazuh

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-03-17); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
wazuh

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-17: 3Mentions · 2026-03-18: 1Mentions · 2026-03-24: 1PoC Mentioned / Linked · 2026-03-18: 1Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-03-24: 1Technical Details · 2026-03-17: 3Technical Details · 2026-03-18: 1Technical Details · 2026-03-24: 103-1703-1803-24
Signal classification3 categories
Disclosure
240.0%
Patch
240.0%
PoC
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-173
Disclosure2Patch1
2026-03-181
PoC1
2026-03-241
Patch1
Full discourse5 posts
  • Gray Hats@the_yellow_fall
    Patch

    Wazuh patches two critical 9.1 CVSS flaws (CVE-2026-25769 &amp; CVE-2026-25770) allowing total cluster takeover. Upgrade to v4.14.3 now to stay protected. #Wazuh #CyberSecurity #InfoSec #Vulnerability #RCE #PrivEsc #PatchNow #OpenSource #ThreatIntel https://securityonline.info/wazuh-security-vulnerabilities-rce-privilege-escalation-patch-v4-14-3/ https://t.co/tAYsLCszNr

    Post summary

    Wazuh released v4.14.3 to address two critical CVEs that could lead to complete cluster takeover, urging users to upgrade immediately.

    05028151.7K
    10.9K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25770 Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 and prior to version 4.14.3, a privilege escal… https://www.cve.org/CVERecord?id=CVE-2026-25770

    Post summary

    The passage announces CVE‑2026‑25770 as a privilege‑escalation flaw affecting Wazuh 3.9.0‑4.14.3, but provides no evidence of exploitation or remediation.

    01010121
    56.7K followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2026-25770: Wazuh has Privilege Escalation t... Cluster creds = root shell via config injection through wazuh-clusterd -&gt; ossec.conf overwrite -&gt; logcollector RCE chai... https://zerodaysignal.com/vulnerability/CVE-2026-25770 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE‑2026‑25770 enables privilege escalation in Wazuh; a configuration injection leads to a root shell, and a linked article suggests a PoC is available.

    0000066
    155 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-25770 - Critical Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 and prior to version 4.14.3, a privilege escalation vulnerability e... https://www.thehackerwire.com/vulnerability/CVE-2026-25770/ https://t.co/6VyXjIki3f

    Post summary

    A critical privilege escalation vulnerability (CVE‑2026‑25770) has been disclosed for Wazuh versions 3.9.0 to 4.14.3, without any PoC, exploit, or patch details provided.

    0000061
    138 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-25770: CRITICAL] A vulnerability in the Wazuh platform allows remote attackers to gain full Root Remote Code Execution. Upgrade to version 4.14.3 to patch this critical security flaw.#cve,CVE-2026-25770,#cybersecurity https://cvefind.com/CVE-2026-25770

    Post summary

    The tweet announces a critical RCE vulnerability in Wazuh (CVE-2026-25770) and advises users to upgrade to version 4.14.3 for remediation.

    0000093
    602 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwazuhwazuh---

Explore more