CVE-2026-25769: Wazuh Cluster vulnerable to Remote Code Execution via Insecure Deserialization
Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.14.2 have a Remote Code Execution (RCE) vulnerability due to Deserialization of Untrusted Data). All Wazuh deployments using cluster mode (master/worker architecture) and any organization with a compromised worker node (e.g., through initial access, insider threat, or supply chain attack) are impacted. An attacker who gains access to a worker node (through any means) can achieve full RCE on the master node with root privileges. Version 4.14.3 fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25769?
CVE-2026-25769 has a high severity rating due to its potential for Remote Code Execution.
How do I fix CVE-2026-25769?
To mitigate CVE-2026-25769, upgrade your Wazuh installation to version 4.14.3 or later.
What versions of Wazuh are affected by CVE-2026-25769?
CVE-2026-25769 affects Wazuh versions from 4.0.0 to 4.14.2.
What can attackers do with CVE-2026-25769?
Attackers exploiting CVE-2026-25769 can execute arbitrary code on the affected system.
Is CVE-2026-25769 related to insecure deserialization?
Yes, CVE-2026-25769 is specifically due to insecure deserialization of untrusted data.