CVE-2026-25790Disclosure(wazuh / wazuh)

LOWCVSS 7.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch wazuh wazuh systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 and prior to version 4.14.3, multiple stack-based buffer overflows exist in the Security Configuration Assessment (SCA) decoder (`wazuh-analysisd`). The use of `sprintf` with a floating-point (`%lf`) format specifier on a fixed-size 128-byte buffer allows a remote attacker to overflow the stack. A specially crafted JSON event can trigger this overflow, leading to a denial of service (crash) or potential RCE on the Wazuh manager. The vulnerability is located in `/src/analysisd/decoders/security_configuration_assessment.c`, within the `FillScanInfo` and `FillCheckEventInfo` functions. In multiple locations, a 128-byte buffer (`char value[OS_SIZE_128];`) is allocated on the stack to hold the string representation of a number from a JSON event. The code checks if the number is an integer or a double. If it's a double, it uses `sprintf(value, "%lf", ...)` to perform the conversion. This `sprintf` call is unbounded. If a floating-point number with a large exponent (e.g., `1.0e150`) is provided, `sprintf` will attempt to write its full string representation (a "1" followed by 150 zeros), which is larger than the 128-byte buffer, corrupting the stack. Version 4.14.3 patches the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wazuh

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
wazuh

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-17: 3Patch / Workaround · 2026-03-17: 1Technical Details · 2026-03-17: 303-17
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-25790 - Wazuh has Stack-Based Buffer Overflow in Security Configuration Assessment JSON Parser Intel Report: https://ift.tt/7XB9jD6

    Post summary

    Alert announces a stack‑based buffer overflow in Wazuh’s JSON parser, providing the CVE identifier and technical details, but no proof of concept or exploitation evidence.

    0000055
    335 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-25790 - Wazuh has Stack-Based Buffer Overflow in Security Configuration Assessment JSON Parser Intel Report: https://ift.tt/3ZVAF7R

    Post summary

    The alert announces CVE-2026-25790, a stack‑based buffer overflow in Wazuh’s Security Configuration Assessment JSON parser, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    0000055
    335 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25790 Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 and prior to version 4.14.3, multiple stack-ba… https://www.cve.org/CVERecord?id=CVE-2026-25790

    Post summary

    The text announces CVE‑2026‑25790 affecting Wazuh versions 3.9.0–4.14.2 as a stack‑based issue, linking to the CVE record.

    00000106
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwazuhwazuh---

Explore more