logo

Critical Wazuh CVSS 10 Vulnerability Details and Proof-of-Concept Released

ID: e518c5ad-35ac-5fe6-a582-1c46b5d479af

STIX ID: report--e518c5ad-35ac-5fe6-a582-1c46b5d479af

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-06-15

Date Updated: 2026-06-15

Author: Do Son

...
...

**Executive Summary:** The report documents a critical CVSS 10 OpenSearch bulk-injection vulnerability in Wazuh 5.0's inventory pipeline allowing authenticated agents to inject privileged OpenSearch bulk operations (including destructive deletes and persistent dashboard payloads) via an unescaped DataValue.index field; affected managers (5.0.0-beta1 to prior to beta3) should be upgraded to 5.0.0-beta3 which includes the patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.