SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-56699

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

Wazuh Manager versions prior to 5.0.0-beta3 are vulnerable due to improper escaping of the DataValue.index field in OpenSearch bulk requests, allowing enrolled agents to inject malicious NDJSON operations. This critical flaw enables attackers to perform unauthorized actions such as document deletion and alert tampering under the manager's admin credentials, compromising the integrity of the SIEM system. Organizations using affected versions should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-56699
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A

Original NVD Description

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Per Wazuh's Security Policy, vulnerabilities affecting only non-GA versions are not eligible for a CVE ID.