CVE-2026-67307: Wazuh before 5.0.0-beta3 Cluster Attribution Spoofing via Inventory Sync
Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the clustername and clusternode fields in inventory-sync Start FlatBuffer messages, while validating only the agentid against the authenticated agent identity. This allows a low-privileged enrolled agent to spoof cluster attribution in indexed inventory and vulnerability documents by forging wazuh.cluster.name values and influencing the document id prefix, potentially tampering with inventory records or, in shared-indexer multi-cluster deployments, poisoning another cluster's records when numeric agent IDs collide.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wazuhto a version that resolves this vulnerability.Fixed in 5.0.0-beta3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-67307?
CVE-2026-67307 has a medium severity rating of 6.3.
How do I fix CVE-2026-67307?
To fix CVE-2026-67307, update Wazuh to version 5.0.0-beta3 or later.
What type of attack does CVE-2026-67307 enable?
CVE-2026-67307 allows a low-privileged agent to spoof cluster attribution via inventory sync.
What versions of Wazuh are affected by CVE-2026-67307?
Wazuh versions before 5.0.0-beta3 are affected by CVE-2026-67307.
What fields are not validated in CVE-2026-67307?
CVE-2026-67307 does not validate the cluster_name and cluster_node fields in specific messages.