CVE-2026-56699: Wazuh Manager - NDJSON Injection in inventory_sync via Agent-Controlled DataValue.index
Published Jul 15, 2026
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Per Wazuh's Security Policy, vulnerabilities affecting only non-GA versions are not eligible for a CVE ID.
Affected Software
1 affected component
Wazuh Wazuh Manager<5.0.0-beta3
Event History
Jul 15, 2026
CVE Published
via MITRE·11:25 AM
Rejected
via MITRE·11:25 AM
Data Sourced
via NVD·12:18 PM
Description
Aug 6, 2026
Rejected
via MITRE·04:42 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-56699?
CVE-2026-56699 has a critical severity rating of 10.
2
How do I fix CVE-2026-56699?
To fix CVE-2026-56699, upgrade Wazuh Manager to version 5.0.0-beta3 or later.
3
What type of attack does CVE-2026-56699 allow?
CVE-2026-56699 allows enrolled agents to inject arbitrary NDJSON operations into bulk requests.
4
Which versions of Wazuh are affected by CVE-2026-56699?
Wazuh Manager versions prior to 5.0.0-beta3 are affected by CVE-2026-56699.
5
What component of Wazuh is impacted by CVE-2026-56699?
CVE-2026-56699 impacts the Wazuh Manager's handling of the DataValue.index field during OpenSearch bulk requests.