CVE-2026-74039
EUVD-2026-6107518.08.2026, 18:19
Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allow_run_as enabled to exhaust CPU resources by submitting arbitrarily deeply nested JSON structures to the POST /security/user/authenticate/run_as endpoint. Attackers can repeatedly submit malformed auth_context bodies with unlimited nesting depth to cause the API framework to consume excessive CPU, denying service to all other API consumers.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| wazuh | wazuh | 4.0.0 ≤ 𝑥 < 4.14.7 |
| wazuh | wazuh | 5.0.0:beta1 |
| wazuh | wazuh | 5.0.0:beta2 |
𝑥
= Vulnerable software versions