IT security platform: Attackers can compromise Wazuh

In the current Wazu version, developers have closed several vulnerabilities. Malware can get onto systems.

listen Print view
A woman presses a symbolic update button.

(Image: Alfa Photo / Shutterstock.com)

1 min. read

The Extended Detection and Response (XDR) and Security Information and Event Management (SIEM) platform Wazuh is vulnerable. Attackers can exploit the open-source application through a total of five security vulnerabilities.

As indicated in the security section of Wazuh's GitHub website, one vulnerability (CVE-2026-30893) is classified as “critical.” In the course of a path traversal attack, attackers can gain unauthorized access to protected paths.

Subsequently, according to the developers, it is possible for attackers to manipulate Python modules, which then load various Wazuh components. This can lead to the execution of malware. Systems are then considered compromised.

Videos by heise

The remaining vulnerabilities are classified as “medium.” These can cause crashes, among other things (including CVE-2026-41499). The developers assure that they have resolved the security issues in version 4.14.4. So far, there are no reports of attackers already targeting instances.

(des)

Don't miss any news – follow us on Facebook, LinkedIn or Mastodon.

This article was originally published in German. It was translated with technical assistance and editorially reviewed before publication.