CVE-2026-56699: Critical NDJSON Injection in Wazuh Manager (CVSS 10.0)
ID: 3d33dfdf-b6b2-5572-8244-a818ba6df4a3
STIX ID: report--3d33dfdf-b6b2-5572-8244-a818ba6df4a3
Feed Name: CosmicBytez Labs
Threat Score
**Critical Wazuh Manager 5.0 beta vulnerability (CVE-2026-56699):** an unauthenticated enrolled agent can inject arbitrary NDJSON into OpenSearch bulk requests via the unsanitized `DataValue.index` field, enabling deletion or tampering of logs and persistent dashboard payloads; upgrade to `Wazuh Manager 5.0.0-beta3` or apply the recommended input-sanitization, allowlisting, and least-privilege keystore mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
