CVE-2026-32983: SSL/TLS Renegotiation DoS in Wazuh Manager authd service
Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiation vulnerability that allows remote attackers to cause a denial of service by sending excessive renegotiation requests. Attackers can exploit the lack of renegotiation limits to consume CPU resources and render the authd service unavailable.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wazuh-manager authd service (wazuh-manager packages)to a version that resolves this vulnerability.Fixed in 4.7.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32983?
CVE-2026-32983 has a high severity rating due to its potential for causing denial of service in the Wazuh Manager authd service.
How do I fix CVE-2026-32983?
To fix CVE-2026-32983, upgrade Wazuh Manager (authd) to version 4.7.4 or later.
What does CVE-2026-32983 affect?
CVE-2026-32983 affects the Wazuh Manager authd service in versions up to and including 4.7.3.
Can CVE-2026-32983 be exploited remotely?
Yes, CVE-2026-32983 can be exploited remotely by attackers sending excessive SSL/TLS renegotiation requests.
What type of vulnerability is CVE-2026-32983?
CVE-2026-32983 is classified as a denial of service (DoS) vulnerability.