ZDI-26-528: Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Wazuh. An attacker must first obtain the ability to execute low-privileged code on a worker node in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.9. The following CVEs are assigned: CVE-2026-28220.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-528?
The severity of ZDI-26-528 is rated as 9.9 based on the CVSS scoring system.
How do I fix ZDI-26-528?
To mitigate ZDI-26-528, ensure that all Wazuh installations are updated to the latest version that addresses this vulnerability.
What type of exploit is associated with ZDI-26-528?
ZDI-26-528 involves a remote code execution vulnerability due to deserialization of untrusted data.
Who can exploit ZDI-26-528?
ZDI-26-528 can be exploited by network-adjacent attackers with low-privileged code execution capabilities on a worker node.
What are the risks of ZDI-26-528?
The risks of ZDI-26-528 include the potential for attackers to execute arbitrary code on affected installations of Wazuh.