CVE-2026-56401: Wazuh - NULL Pointer Dereference in inventory_sync DataValue FlatBuffer Handling
Published Jul 8, 2026
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
5 affected components
Wazuh wazuh-modulesd<5.0.0-beta3
Wazuh Wazuh<5.0.0
Wazuh Wazuh=5.0.0-alpha0
Wazuh Wazuh=5.0.0-beta1
Wazuh Wazuh=5.0.0-beta2
Remediation
Event History
Jul 8, 2026
CVE Published
via MITRE·01:49 PM
Rejected
via MITRE·01:49 PM
Data Sourced
via NVD·02:17 PM
Description
Jul 15, 2026
Rejected
via MITRE·11:42 AM
Frequently Asked Questions
1
What is the risk associated with CVE-2026-56401?
CVE-2026-56401 has a risk score of 38, indicating medium severity.
2
What is the severity level of CVE-2026-56401?
CVE-2026-56401 has a severity level of medium with a score of 6.5 due to its null pointer dereference vulnerability.
3
How does the null pointer dereference in CVE-2026-56401 occur?
CVE-2026-56401 occurs when an enrolled agent sends a DataValue message that omits the optional id field, leading to a crash in wazuh-modulesd.
4
What versions of Wazuh are affected by CVE-2026-56401?
CVE-2026-56401 affects Wazuh wazuh-modulesd versions prior to 5.0.0-beta3.
5
How can I mitigate the vulnerability CVE-2026-56401?
Mitigation for CVE-2026-56401 involves upgrading to Wazuh wazuh-modulesd version 5.0.0-beta3 or later.