ZDI-26-527: Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Wazuh. An attacker must first obtain the ability to execute low-privileged code on a worker node in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.9. The following CVEs are assigned: CVE-2026-44901.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-527?
ZDI-26-527 has a CVSS rating of 9.9, indicating it is a critical vulnerability.
How do I fix ZDI-26-527?
To mitigate ZDI-26-527, it is recommended to update to the latest version of Wazuh that addresses this vulnerability.
Can ZDI-26-527 be exploited remotely?
Yes, ZDI-26-527 can be exploited by network-adjacent attackers to achieve remote code execution.
What conditions must be met for ZDI-26-527 to be exploited?
An attacker must first gain the ability to execute low-privileged code on a worker node to exploit ZDI-26-527.
What software is affected by ZDI-26-527?
ZDI-26-527 affects installations of Wazuh that utilize the DAPI protocol.