logo

CVE-2026-25769: Critical Remote Code Execution in Wazuh via Unsafe Deserialization

ID: ab0adcee-b5ab-57ed-85e2-2337bbc29234

STIX ID: report--ab0adcee-b5ab-57ed-85e2-2337bbc29234

Feed Name: Resecurity

Threat Score
90/100

Date Published: 2026-04-08

Date Updated: 2026-07-27

...
...

Critical remote code execution vulnerability in Wazuh cluster communication (CVE-2026-25769) allows a compromised worker to craft JSON that, via an unsafe object_hook, imports arbitrary modules and returns callables that are executed on the master. The report contains vulnerable code snippets, an exploit PoC demonstrating a reverse shell, affected versions (4.0.0–4.14.2), impact analysis (full cluster compromise, root access, data exfiltration), and mitigation guidance (upgrade to 4.14.3+, restrict port 1516, network segmentation, key rotation).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.