Loading market data...
← Back to CVE feed

CVE-2026-56699

CRITICAL CVSS 10.0 View on NVD ↗

Description

Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON operations. Attackers can smuggle delete, index, or update operations into bulk requests executed under the manager's admin credentials, enabling document deletion, alert tampering, and cross-agent SIEM state manipulation.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published: Jul 15, 2026 12:18 UTC Modified: Jul 15, 2026 21:01 UTC