Medium severity6.5NVD Advisory· Published Aug 18, 2026· Updated Oct 1, 2026
CVE-2026-74039
CVE-2026-74039
Description
Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allow_run_as enabled to exhaust CPU resources by submitting arbitrarily deeply nested JSON structures to the POST /security/user/authenticate/run_as endpoint. Attackers can repeatedly submit malformed auth_context bodies with unlimited nesting depth to cause the API framework to consume excessive CPU, denying service to all other API consumers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
3- github.com/wazuh/wazuh/pull/37034nvdIssue TrackingPatch
- github.com/wazuh/wazuh/security/advisories/GHSA-5vh8-34r8-q74qnvdExploitMitigationVendor Advisory
- www.vulncheck.com/advisories/wazuh-api-dos-via-deeply-nested-json-auth-contextnvdThird Party Advisory
News mentions
1- Wazuh: 17 Vulnerabilities Disclosed Together, Affecting Cluster and API FunctionsVypr Intelligence · Aug 19, 2026