VYPR

Wazuh Manager

by Wazuh

Source repositories

CVEs (8)

  • CVE-2026-25770CriMar 17, 2026
    risk 0.52cvss 9.1epss 0.01

    Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 and prior to version 4.14.3, a privilege escalation vulnerability exists in the Wazuh Manager's cluster synchronization protocol. The `wazuh-clusterd` service…

  • CVE-2026-44252HigAug 19, 2026
    risk 0.50cvss 8.8epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.5, Wazuh Manager allows a low-privilege read-only API user with manager:read permission to retrieve the cluster key from the element in ossec.conf through GET…

  • CVE-2021-41821MedSep 29, 2021
    risk 0.42cvss 6.5epss 0.01

    Wazuh Manager in Wazuh through 4.1.5 is affected by a remote Integer Underflow vulnerability that might lead to denial of service. A crafted message must be sent from an authenticated agent to the manager.

  • CVE-2025-15616MedMar 27, 2026
    risk 0.37cvss 6.7epss 0.02

    Wazuh wazuh-agent and wazuh-manager versions 2.1.0 before 4.8.0 contain multiple shell injection and untrusted search path vulnerabilities that allow attackers to execute arbitrary commands through various components including logcollector configuration, maild SMTP server tags,…

  • CVE-2025-15615MedMar 27, 2026
    risk 0.31cvss 5.8epss 0.01

    Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiation vulnerability that allows remote attackers to cause a denial of service by sending excessive renegotiation requests. Attackers…

  • CVE-2026-32983MedMar 27, 2026
    risk 0.31cvss 5.8epss 0.00

    Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiation vulnerability that allows remote attackers to cause a denial of service by sending excessive renegotiation requests. Attackers…

  • CVE-2026-39359HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through 4.10.3 and 4.11.0 through 4.14.4, a logic flaw affects the Wazuh Manager's enrollment daemon (authd) and synchronization daemon (remoted). The authd process…

  • CVE-2026-56699Jul 15, 2026
    risk 0.00cvss epss 0.00

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Per Wazuh's Security Policy, vulnerabilities affecting only non-GA versions are not eligible for a CVE ID.