SecAlerts
W

Wazuh

Security Risk Profile

51
/100
medium

Security Risk Score

Comprehensive risk assessment based on 88 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from November 29, 2018 to present

88
Total CVEs
56
Critical+High
1
Exploited
46
Unpatched

Threat Assessment

Avg CVSS
7.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
46
Critical/High
Risk Level
51/100
medium
⚠️ 1 Active Exploits📈 6 in Last 30 Days

Severity Distribution

Critical
15
High
41
Medium
24
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
2

Age Distribution

Common Weaknesses (CWE)

1
Path Traversal
11
2
Buffer Overflow
9
3
Null Pointer Dereference
8
4
Integer Underflow
5
5
Input Validation
3

Most Affected Products

1. Wazuh Wazuh149
2. Wazuh Wazuh Manager8
3. Wazuh Wazuh Agent3
4. Wazuh3
5. Wazuh Wazuh agent for Windows2

Recent Vulnerabilities

See more →
CVE-2026-61802
CVSS 6.5medium

Wazuh discloses cleartext cluster key to low-privilege API users via GET /cluster/local/config

Aug 27, 2026🔧 No Patch
CVE-2026-61800
CVSS 9.1critical

Wazuh cluster worker file sync allows arbitrary file write under /var/ossec (incomplete fix for CVE-2026-30893)

Aug 27, 2026🔧 No Patch
CVE-2026-61783
CVSS 7.0high

Wazuh: RBAC permission-effect check in mask_sensitive_config allows low-privilege users to read cluster.key

Aug 27, 2026🔧 No Patch
CVE-2026-54084
CVSS 5.3medium

Wazuh agent enrollment NULL pointer dereference via malformed manager response

Aug 27, 2026🔧 No Patch
CVE-2026-54085
CVSS 7.1high

Wazuh: Missing input validation in multiple active response scripts allows argument injection

Aug 27, 2026🔧 No Patch
CVE-2026-54083
CVSS 8.1high

Wazuh: Path traversal in ip-customblock active response allows arbitrary file creation and deletion

Aug 27, 2026🔧 No Patch
CVE-2026-49392
CVSS 5.3medium

Wazuh: Local SQL injection in FIM db due to path lookup interpolation in wazuh-syscheckd

Aug 19, 2026🔧 No Patch
CVE-2026-44256
CVSS 5.3medium

Wazuh: CRLF Log Injection via Unsanitized Basic-Auth Username

Aug 19, 2026
CVE-2026-45798
CVSS 7.5high

Wazuh: Pre-auth stack-buffer-overflow in compare_wazuh_versions reachable from wazuh-authd (TCP/1515) via crafted enrollment V: field

Aug 19, 2026🔧 No Patch
CVE-2026-49441
CVSS 9.1critical

Wazuh : peer-controlled metadata key in process_files_from_worker non-merged branch allows arbitrary file write under WAZUH_PATH on Wazuh manager

Aug 19, 2026🔧 No Patch

Monitor Wazuh in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

Wazuh Security Vulnerabilities & Risk Score | 88 CVEs | SecAlerts - SecAlerts