ZDI-CAN-30062: ZDI-26-528: Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Wazuh. An attacker must first obtain the ability to execute low-privileged code on a worker node in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.9. The following CVEs are assigned: CVE-2026-28220.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-30062?
ZDI-CAN-30062 has a CVSS rating of 9.9, indicating critical severity.
How do I fix ZDI-CAN-30062?
Fixing ZDI-CAN-30062 involves applying the latest security patches provided by Wazuh.
What type of exploit does ZDI-CAN-30062 allow?
ZDI-CAN-30062 allows network-adjacent attackers to execute arbitrary code due to deserialization of untrusted data.
Who can exploit ZDI-CAN-30062?
Network-adjacent attackers who have the ability to execute low-privileged code on a worker node can exploit ZDI-CAN-30062.
What systems are affected by ZDI-CAN-30062?
ZDI-CAN-30062 affects installations of Wazuh that are vulnerable to the DAPI Protocol deserialization issue.