SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-61802

MEDIUM · CVSS 6.5 EPSS 0.41% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Wazuh versions 4.14.0 through 4.14.6 contain a vulnerability that allows low-privilege API users to access the cleartext cluster key through an improperly secured configuration endpoint. This exposure can lead to unauthorized authentication and potential remote code execution within the cluster, posing a significant risk to the integrity and security of the environment. Organizations using affected versions, particularly those with accounts assigned the readonly or cluster_readonly roles, should prioritize upgrading to version 4.14.7 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-61802
Severity
MEDIUM
CVSS
6.5
EPSS
0.41%

Original NVD Description

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.14.0 through 4.14.6, a low-privilege API user can read the cleartext cluster key from a configuration endpoint that fails to redact it. The REST API provides a masking control, mask_sensitive_config, that redacts sensitive fields such as authd.pass and cluster.key from configuration responses for users who lack update-config permission, and every config-read endpoint carries this decorator except GET /cluster/local/config. That endpoint, backed by read_config_wrapper, is gated only by cluster:read and returns the local node's cluster configuration including the cleartext key, whereas its siblings return the same value masked. As a result, any account with the default readonly or cluster_readonly role, which is explicitly denied update-config precisely so it cannot view secrets, receives the real cluster key. Because the cluster key authenticates and encrypts traffic between cluster nodes, disclosing it to an unprivileged account provides the authentication precondition for the cluster-peer remote code execution chains established by prior advisories. This issue is fixed in version 4.14.

Related CVEs

Other vulnerabilities affecting the same vendor(s)