CVE-2026-28220

Wazuh · Wazuh

Wazuh is susceptible to a deserialization vulnerability, which could allow a highly privileged attacker to achieve remote code execution.

Executive summary

A critical deserialization vulnerability in the Wazuh platform could allow an authenticated user with high privileges to execute arbitrary code or compromise system integrity.

Vulnerability

This vulnerability involves the deserialization of untrusted data. An attacker with high-level privileges can supply malicious serialized objects to the platform, leading to potential remote code execution or total system compromise.

Business impact

Successful exploitation of this flaw allows for total system impact, including loss of confidentiality, integrity, and availability. Given the CVSS score of 8.4, this poses a severe risk to the security monitoring infrastructure, potentially allowing an attacker to disable security controls or pivot into the wider network.

Remediation

Immediate Action: Upgrade to Wazuh version 4.14.5 or higher to resolve the deserialization flaw.

Proactive Monitoring: Monitor for suspicious process execution or unusual deserialization-related errors within internal platform logs.

Compensating Controls: Restrict access to administrative interfaces and ensure that the Wazuh manager instance is isolated within a secure network segment.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Because this vulnerability affects the core security platform, it requires immediate attention. Organizations should prioritize patching all Wazuh components to version 4.14.5 to mitigate the risk of remote code execution and maintain the integrity of their security monitoring environment.