SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-54085

HIGH · CVSS 7.1 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Multiple active response scripts in Wazuh versions 4.2.0 through 4.14.6 are vulnerable to argument injection due to improper validation of attacker-influenced alert fields, specifically the srcip and dstuser fields. This flaw allows an attacker to execute arbitrary commands with elevated privileges, potentially compromising system security and account management on Windows systems. Organizations using affected Wazuh versions should prioritize upgrading to version 4.14.7 to mitigate this high-severity vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-54085
Severity
HIGH
CVSS
7.1
EPSS
0.24%
Windows

Original NVD Description

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.2.0 through 4.14.6, multiple active response scripts pass attacker-influenced alert fields to privileged system commands without validating their format, allowing argument injection into tools that run as root. Five of the eight scripts that handle the srcip field, route-null.c, netsh.c, pf.c, npf.c, and ipfw.c, omit the get_ip_version() check that rejects non-IP input, and disable-account.c passes the dstuser field to passwd/chuser with only a comparison against "root". An attacker who can inject crafted log events, for example via syslog, can supply srcip or dstuser values that, when an active response rule triggers, are passed unvalidated to firewall and account-management commands such as pfctl, npfctl, ipfw, route, netsh, and passwd. This enables injecting additional command arguments, and on Windows the unquoted CreateProcess command-line concatenation in wpopenv() lets a srcip containing spaces add further arguments, while disable-account.c can be abused to lock arbitrary system accounts. This issue is fixed in version 4.14.7.

Related CVEs

Other vulnerabilities affecting the same vendor(s)