SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-74039

MEDIUM · CVSS 6.5 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Authenticated attackers with the "allow_run_as" feature enabled in Wazuh versions prior to 4.14.7 and 5.0.0-beta2 can exploit a denial of service vulnerability by submitting deeply nested JSON structures to the authentication endpoint. This can lead to excessive CPU resource consumption, effectively denying service to legitimate API users. Organizations using affected versions should prioritize patching to mitigate potential disruptions to their services.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-74039
Severity
MEDIUM
CVSS
6.5
EPSS
0.36%

Original NVD Description

Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allow_run_as enabled to exhaust CPU resources by submitting arbitrarily deeply nested JSON structures to the POST /security/user/authenticate/run_as endpoint. Attackers can repeatedly submit malformed auth_context bodies with unlimited nesting depth to cause the API framework to consume excessive CPU, denying service to all other API consumers.

Related CVEs

Other vulnerabilities affecting the same vendor(s)