CyberRota Analysis
AI-GeneratedWazuh Manager versions prior to 5.0.0-beta3 are vulnerable due to improper escaping of the DataValue.index field in OpenSearch bulk requests, allowing enrolled agents to inject malicious NDJSON operations. This critical flaw enables attackers to perform unauthorized actions such as document deletion and alert tampering under the manager's admin credentials, compromising the integrity of the SIEM system. Organizations using affected versions should prioritize immediate updates to mitigate the risk of exploitation.
Original NVD Description
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Per Wazuh's Security Policy, vulnerabilities affecting only non-GA versions are not eligible for a CVE ID.