CVE-2026-56699: Wazuh Manager - NDJSON Injection in inventory_sync via Agent-Controlled DataValue.index
Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON operations. Attackers can smuggle delete, index, or update operations into bulk requests executed under the manager's admin credentials, enabling document deletion, alert tampering, and cross-agent SIEM state manipulation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wazuh Managerto a version that resolves this vulnerability.Fixed in 5.0.0-beta3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56699?
CVE-2026-56699 has a critical severity rating of 10.
How do I fix CVE-2026-56699?
To fix CVE-2026-56699, upgrade Wazuh Manager to version 5.0.0-beta3 or later.
What type of attack does CVE-2026-56699 allow?
CVE-2026-56699 allows enrolled agents to inject arbitrary NDJSON operations into bulk requests.
Which versions of Wazuh are affected by CVE-2026-56699?
Wazuh Manager versions prior to 5.0.0-beta3 are affected by CVE-2026-56699.
What component of Wazuh is impacted by CVE-2026-56699?
CVE-2026-56699 impacts the Wazuh Manager's handling of the DataValue.index field during OpenSearch bulk requests.