CVE-2026-25769: Critical Remote Code Execution in Wazuh via Unsafe Deserialization
ID: ab0adcee-b5ab-57ed-85e2-2337bbc29234
STIX ID: report--ab0adcee-b5ab-57ed-85e2-2337bbc29234
Feed Name: Resecurity
Critical remote code execution vulnerability in Wazuh cluster communication (CVE-2026-25769) allows a compromised worker to craft JSON that, via an unsafe object_hook, imports arbitrary modules and returns callables that are executed on the master. The report contains vulnerable code snippets, an exploit PoC demonstrating a reverse shell, affected versions (4.0.0–4.14.2), impact analysis (full cluster compromise, root access, data exfiltration), and mitigation guidance (upgrade to 4.14.3+, restrict port 1516, network segmentation, key rotation).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
