CVE-2026-26206Disclosure(wazuh / wazuh)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to before version 4.14.4, Wazuh's server API brute-force protection for POST /security/user/authenticate can be bypassed by sending concurrent authentication requests. Although the configured threshold (max_login_attempts, default 50) is enforced correctly for sequential requests, a parallel burst allows significantly more failed login attempts to be processed before the IP block is applied. This enables an attacker to perform more password guesses than the configured policy intends (e.g., 100 attempts processed where 50 should be allowed). This issue has been patched in version 4.14.4.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-307CWE-362CWE-367

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wazuh

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
wazuh

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-29: 2Technical Details · 2026-04-29: 204-29
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26206 Brute-Force Protection Bypass in Wazuh Server API via Concurrent Authentication Requests https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26206

    Post summary

    The post announces CVE‑2026‑26206, a vulnerability in Wazuh Server API that allows bypassing brute‑force protection by sending concurrent authentication requests.

    0000043
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-26206 Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to before version 4.14.4, Wazuh's server API brute-fo… https://www.cve.org/CVERecord?id=CVE-2026-26206

    Post summary

    The snippet provides a brief, incomplete description of a Wazuh CVE (API brute‑force on specific versions) but offers no details on exploits, patches, or proof of concept.

    0000093
    57.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwazuhwazuh---

Explore more