ZDI-CAN-30086: ZDI-26-527: Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Wazuh. An attacker must first obtain the ability to execute low-privileged code on a worker node in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.9. The following CVEs are assigned: CVE-2026-44901.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-30086?
The severity of ZDI-CAN-30086 is rated at 9.9, indicating a critical vulnerability.
How do I fix ZDI-CAN-30086?
To fix ZDI-CAN-30086, upgrade to the latest version of Wazuh that addresses this deserialization vulnerability.
What impact does ZDI-CAN-30086 have on Wazuh installations?
ZDI-CAN-30086 allows network-adjacent attackers to execute arbitrary code on affected Wazuh installations.
Who can exploit ZDI-CAN-30086?
An attacker must first obtain the ability to execute low-privileged code on a worker node to exploit ZDI-CAN-30086.
What kind of vulnerability is ZDI-CAN-30086 classified as?
ZDI-CAN-30086 is classified as a remote code execution vulnerability due to deserialization of untrusted data.