CVE-2026-30893Disclosure(wazuh / wazuh)

MEDIUMCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch wazuh wazuh systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to before version 4.14.4, a path traversal vulnerability in Wazuh's cluster synchronization extraction routine allows an authenticated cluster peer to write arbitrary files outside the intended extraction directory on other cluster nodes. This can be escalated to code execution in the Wazuh service context by overwriting Python modules loaded by Wazuh components (proof of concept available as separate attachment). In deployments where the cluster daemon runs with elevated privileges, system-level compromise is possible. This issue has been patched in version 4.14.4.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-73

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wazuh

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 16 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 13 signals
  • Disclosure: 6 classified signals
  • General: 3 classified signals
  • Peaked 3d ago at 4 mentions (2026-05-12); latest day: 1
  • 16 total mentions across 9 days

Affected systems

Vendors
Products
wazuh

Deep dive

Activity timeline16 mentions / 9d
01234Mentions · 2026-04-29: 2Mentions · 2026-04-30: 1Mentions · 2026-05-01: 1Mentions · 2026-05-06: 1Mentions · 2026-05-11: 2Mentions · 2026-05-12: 4Mentions · 2026-05-13: 3Mentions · 2026-05-15: 1Mentions · 2026-05-22: 1PoC Mentioned / Linked · 2026-05-01: 1PoC Mentioned / Linked · 2026-05-12: 1Exploit Tool / Code · 2026-05-12: 1Patch / Workaround · 2026-04-30: 1Patch / Workaround · 2026-05-01: 1Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-12: 2Patch / Workaround · 2026-05-13: 2Patch / Workaround · 2026-05-22: 1Technical Details · 2026-04-29: 2Technical Details · 2026-04-30: 1Technical Details · 2026-05-01: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-12: 4Technical Details · 2026-05-13: 1Technical Details · 2026-05-15: 1Technical Details · 2026-05-22: 104-2904-3005-0105-0605-1105-1205-1305-1505-22
Signal classification4 categories
Disclosure
637.5%
Patch
637.5%
General
318.8%
PoC
16.3%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-04-292
Disclosure2
2026-04-301
Patch1
2026-05-011
Disclosure1
2026-05-061
General1
2026-05-112
General1Patch1
2026-05-124
Disclosure2Patch1PoC1
2026-05-133
General1Patch2
2026-05-151
Disclosure1
2026-05-221
Patch1
Full discourse16 posts
  • The Shadowserver Foundation@Shadowserver
    Patch

    We are scanning & reporting daily Wazuh CVE-2026-30893 (CVSS 9.9) vulnerable instances, with over 3500 IPs seen unpatched on 2026-05-10. See advisory & update to latest version: https://github.com/wazuh/wazuh/security/advisories/GHSA-m8rw-v4f6-8787 ... Worth keeping your security platforms up to date! https://t.co/SeXZaPYDS7

    Post summary

    The tweet highlights a high‑severity CVE in Wazuh, notes thousands of unpatched hosts, and urges users to apply the latest patch via the provided advisory link.

    210036236.4K
    21.9K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Wazuh patches a critical 9.0 CVSS flaw (CVE-2026-30893) in cluster sync. Malicious peers can achieve RCE and lateral movement. Upgrade your clusters now. #Wazuh #CyberSecurity #InfoSec #RCE #Vulnerability #SysAdmin #OpenSource #PatchNow https://securityonline.info/wazuh-cluster-sync-vulnerability-cve-2026-30893-rce-guide/ https://t.co/CZnQBQlotl

    Post summary

    Wazuh has released a patch for CVE‑2026‑30893, a critical 9.0‑score vulnerability enabling remote code execution and lateral movement in cluster sync. Administrators are urged to upgrade their clusters immediately.

    0901681.4K
    12.5K followersView on X
  • IT-Connect.fr@ITConnect_fr
    Patch

    ➡️ Wazuh - Un patch est disponible Une faille de sécurité critique, associée à la référence CVE-2026-30893 et affichant un score CVSS de 9.9, a été révélée récemment au sein de #Wazuh 🛡️ Comment se protéger ? https://www.it-connect.fr/wazuh-cve-2026-30893-un-patch-est-disponible-pour-cette-faille-critique/ https://www.it-connect.fr/wazuh-cve-2026-30893-un-patch-est-disponible-pour-cette-faille-critique/

    Post summary

    The post announces a critical CVE against Wazuh (CVE-2026-30893) with a high CVSS score and notes that a patch is available, focusing on the mitigation.

    160841.4K
    11.5K followersView on X
  • Misbar | مسبار@MisbarSec
    Disclosure

    📌 ثغرة خطيرة في منصة Wazuh تم الكشف عن ثغرة خطيرة في آلية المزامنة في منصة Wazuh المفتوحة المصدر للكشف عن التهديدات والاستجابة لها. تسمح هذه الثغرة، التي تم تتبعها كـ CVE-2026-30893، بالتحرك الجانبي. يمكن للمهاجمين استغلال هذه الثغرة للوصول غير المصرح به إلى الأنظمة المتضررة. يُنصح بـ تحديث الأنظمة المتضررة على الفور. 🔗 للمزيد: https://securityonline.info/wazuh-cluster-sync-vulnerability-cve-2026-30893-rce-guide/

    Post summary

    A new critical vulnerability (CVE-2026-30893) in Wazuh’s synchronization mechanism has been disclosed, enabling lateral movement and unauthorized access. A patch is recommended and a reference guide is linked for remediation.

    00031413
    267 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos Wazuh ❗ CVE-2026-30893 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-wazuh-2/ https://t.co/pznViozoJZ

    Post summary

    The tweet announces a CVE‑2026‑30893 vulnerability in Wazuh products and links to external resources for more information, but it does not provide specifics on exploitation, PoC, patching, or technical details.

    01020119
    6.7K followersView on X
  • The Shadowserver Foundation@Shadowserver
    General

    IP data for your network/constituency shared in Vulnerable HTTP reporting, tagged 'cve-2026-30893: https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/ Public Dashboard tree map view: https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=http_vulnerable&source=http_vulnerable6&tag=cve-2026-30893%2B&data_set=count&scale=log&auto_update=on NVD entry: https://nvd.nist.gov/vuln/detail/CVE-2026-30893 #CyberCivilDefense

    Post summary

    The post references a new CVE (CVE‑2026‑30893) and provides reporting links but offers no details on exploitation, patches, or technical specifics.

    01011910
    21.8K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical path traversal vulnerability in #Wazuh (Open Source XDR & SIEM) CVE-2026-30893 CVSS: 9.9. Exploitation can lead to remote code execution #RCE! #Patch #Patch #Patch https://github.com/wazuh/wazuh/security/advisories/GHSA-m8rw-v4f6-8787

    Post summary

    The tweet alerts about a critical path traversal flaw (CVE‑2026‑30893) in Wazuh with a CVSS score of 9.9, warns of potential remote code execution, and references a GitHub advisory that provides a patch.

    02000251
    7.2K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    CVE-2026-30893 Wazuh cluster sync path traversal in decompress_files() enables arbitrary file write and code execution from authenticated cluster peer https://github.com/wazuh/wazuh/security/advisories/GHSA-m8rw-v4f6-8787

    Post summary

    Wazuh cluster sync contains a path traversal vulnerability in decompress_files() allowing an authenticated peer to write arbitrary files and execute code, as outlined in the GitHub advisory.

    00010371
    6.9K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-30893 (CVSS 9.0) Wazuh 4.4.0-4.14.3: Path traversal in cluster sync enables authenticated attackers to write arbitrary files & achieve RCE. Patch to 4.14.4 immediately. #CVE #Vulnerability #PatchNow https://t.co/voM2VrR3iC

    Post summary

    The post alerts users to a critical path traversal flaw in Wazuh (CVE-2026-30893) that permits authenticated attackers to write files and achieve remote code execution, urging an immediate update to version 4.14.4.

    0000058
    30 followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosure

    Wazuh CVE-2026-30893: Cluster Sync Flaw Enables Full RCE https://thecybrdef.com/wazuh-cve-2026-30893-cluster-sync-rce-vulnerability/ #Cyberupdates #Cybertechnews #Cybersecurity

    Post summary

    The text announces a new CVE-2026-30893 against Wazuh, describing a cluster‑sync flaw that permits full remote code execution.

    0000039
    9 followersView on X
  • thibault@akril
    Patch

    [IT-Connect] - Wazuh – CVE-2026-30893 : un patch est disponible pour cette faille critique - https://www.it-connect.fr/wazuh-cve-2026-30893-un-patch-est-disponible-pour-cette-faille-critique/ 👌😁

    Post summary

    The post announces that a patch is available to mitigate the critical CVE-2026-30893 flaw in Wazuh.

    0000032
    697 followersView on X
  • Harishraam@unknownmatter19
    Disclosure

    Wazuh CVE-2026-30893: Cluster Sync Flaw Enables Full RCE https://thecybrdef.com/wazuh-cve-2026-30893-cluster-sync-rce-vulnerability/ #Cyberupdates #Cybertechnews #Cybersecurity

    Post summary

    A new CVE (2026-30893) affecting Wazuh’s cluster sync feature is disclosed, indicating a full remote code execution vulnerability.

    0000033
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼️#PoC: Proof of Concept per lo sfruttamento della vulnerabilità CVE-2026-30893, relativa a #Wazuh, risulta disponibile in rete Rischio:🔴 Tra le tipologie 🔸Arbitrary Code Execution 🔗https://www.acn.gov.it/portale/w/wazuh-poc-pubblico-per-lo-sfruttamento-della-cve-2026-30893 ⚠️Si raccomanda l’aggiornamento… https://t.co/lItxU2xNzi

    Post summary

    A PoC and an advisory for CVE‑2026‑30893 on Wazuh are publicly available, highlighting an arbitrary code execution flaw and recommending a patch.

    0000075
    611 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-30893: Wazuh Path Traversal Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04fG4BM0

    Post summary

    The article is a general discussion of a path traversal vulnerability in Wazuh, lacking explicit PoC, exploit code, or immediate patch details.

    0000047
    29 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30893 Path Traversal and Arbitrary File Write in Wazuh Cluster Synchronization 4.4.0-4.14.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30893

    Post summary

    The text announces a newly disclosed CVE involving path traversal and arbitrary file write in Wazuh Cluster Synchronization, with no further details on exploitation or mitigation.

    0000042
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30893 Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to before version 4.14.4, a path traversal vulnerabil… https://www.cve.org/CVERecord?id=CVE-2026-30893

    Post summary

    CVE-2026-30893 is a path traversal vulnerability in Wazuh versions 4.4.0 through 4.14.3; no PoC, exploit, or patch details are provided.

    00000104
    57.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwazuhwazuh---

Explore more