Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-56699: Wazuh Manager - Malicious Agent Can Delete or Alter SIEM Data

CVE-2026-56699 CVE-2026-56699
Summary

A vulnerability in Wazuh Manager before version 5.0.0-beta3 allows an enrolled agent to delete or alter data in the SIEM system. This could lead to deleted alerts, tampered data, or other security information being manipulated. Wazuh Manager users should update to version 5.0.0-beta3 or later to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
wazuh wazuh < 5.0.0-beta3
Original title
Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON operations. Attackers can ...
Original description
Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON operations. Attackers can smuggle delete, index, or update operations into bulk requests executed under the manager's admin credentials, enabling document deletion, alert tampering, and cross-agent SIEM state manipulation.
nvd CVSS3.1 10.0
nvd CVSS4.0 10.0
Vulnerability type
CWE-74 Injection
Published: 15 Jul 2026 · Updated: 20 Jul 2026 · First seen: 15 Jul 2026