9
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H
Description
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to before version 4.14.4, a path traversal vulnerability in Wazuh's cluster synchronization extraction routine allows an authenticated cluster peer to write arbitrary files outside the intended extraction directory on other cluster nodes. This can be escalated to code execution in the Wazuh service context by overwriting Python modules loaded by Wazuh components (proof of concept available as separate attachment). In deployments where the cluster daemon runs with elevated privileges, system-level compromise is possible. This issue has been patched in version 4.14.4.
AI Analysis
Path traversal vulnerability in Wazuh's cluster synchronization extraction routine allowing arbitrary file write and code execution
Basic Information
ID
CVE-2026-30893
Source
GitHub_M
Published
Apr 29, 2026 at 17:55
Affected Product
Vendor
wazuh
Product
wazuh
Version
>= 4.4.0, < 4.14.4
Affected Versions
wazuh wazuh >= 4.4.0, < 4.14.4
CWE Classification
AI Assessment
AI Score
9 / 10
AI Severity
Critical
Vendor
Wazuh
Product
Wazuh
Version
4.4.0 to 4.14.3