Medium severity5.3NVD Advisory· Published Aug 19, 2026· Updated Sep 18, 2026
CVE-2026-44255
CVE-2026-44255
Description
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, AuthenticationManager.check_user() in framework/wazuh/rbac/orm.py performs check_password_hash() only when the supplied username exists. A nonexistent username returns immediately, while a valid username causes an expensive bcrypt calculation. An unauthenticated remote attacker can compare authentication response times to enumerate valid Wazuh usernames and use that information in subsequent credential attacks. This issue is fixed in versions 4.14.6 and 5.0.0-beta2.
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/wazuh/wazuh/commit/5ecea7b38b998407cb0d205467dd247140a0f981nvdPatch
- github.com/wazuh/wazuh/pull/35757nvdIssue TrackingPatch
- github.com/wazuh/wazuh/security/advisories/GHSA-3978-44q9-9px9nvdExploitVendor Advisory
- github.com/wazuh/wazuh/releases/tag/v4.14.6nvdRelease Notes
- github.com/wazuh/wazuh/releases/tag/v5.0.0-beta2nvdRelease Notes
News mentions
1- Wazuh: 17 Vulnerabilities Disclosed Together, Affecting Cluster and API FunctionsVypr Intelligence · Aug 19, 2026