High severity7.1NVD Advisory· Published Aug 18, 2026· Updated Oct 1, 2026
CVE-2026-74038
CVE-2026-74038
Description
Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause denial of service by enrolling an agent with a dot-sequence name such as ".." through the enrollment port. Attackers exploit insufficient validation in OS_IsValidName() and unsafe path concatenation in delete_diff() to resolve the traversal to the parent queue directory, causing its subdirectories to be removed and stopping all Wazuh services requiring manual recovery.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
3- github.com/wazuh/wazuh/pull/35833nvdIssue TrackingPatch
- github.com/wazuh/wazuh/security/advisories/GHSA-573w-mqw4-jvmrnvdExploitMitigationVendor Advisory
- www.vulncheck.com/advisories/wazuh-path-traversal-dos-via-agent-enrollmentnvdThird Party Advisory
News mentions
1- Wazuh: 17 Vulnerabilities Disclosed Together, Affecting Cluster and API FunctionsVypr Intelligence · Aug 19, 2026