Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-61783

Опубликовано: 28 авг. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.14.0 through 4.14.6, an authenticated low-privilege user can read the cluster secret from the manager configuration because the logic that masks sensitive values is disabled by any update-config RBAC rule, including an explicit deny. The mask_sensitive_config() decorator applies masking only when _has_update_permissions() returns false, but that gate treats a user as able to update the config whenever a  manager:update_config  or  cluster:update_config  rule exists, without ever checking whether the rule's effect is allow or deny. Because a deny rule is stored as a real entry, a read-only account that is hardened by explicitly denying config edits is counted as having update permission, which turns masking off. A single authenticated GET request to the configuration endpoint with  raw=true  then returns the verbatim ossec.conf XML with  cluster.key

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*:*
Версия от 4.14.0 (включая) до 4.14.7 (исключая)

EPSS

Процентиль: 15%
0.00239
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.5
fstec
около 1 месяца назад

Уязвимость функции mask_sensitive_config() платформы для мониторинга безопасности и обнаружения угроз Wazuh, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 15%
0.00239
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200