logo

Critical Wazuh Vulnerability Enables Lateral Movement and Root Access

ID: 789faae9-5bc8-58b3-a6d8-8afbb9df701d

STIX ID: report--789faae9-5bc8-58b3-a6d8-8afbb9df701d

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Ddos

...
...

Wazuh patched CVE-2026-30893, a critical (CVSS 9.0) path traversal in its cluster synchronization process that allows an authenticated peer to craft archives with traversal paths and overwrite arbitrary files on receiving nodes, potentially achieving remote code execution and lateral spread across clusters; the impact ranges from service-level code execution to full system takeover in containerized/root deployments, and administrators are urged to apply the released fix immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.