What is CVE-2026-41424?
CVE-2026-41424 is an authentication flaw in the Wazuh platform. Incorrect usage of `request.get("user")` instead of token-based user info impacts Wazuh instances from 4.9.0 to 4.10.4 and 4.14.6, potentially allowing privilege escalation. Affected users should immediately upgrade to a patched version.
Azərbaycanca: CVE-2026-41424 Wazuh platformunda autentifikasiya zəifliyidir. 4.9.0-dən 4.10.4-ə və 4.14.6 versiyalarına qədər API sorğularında current_user olaraq yanlış parametr (`request.get("user")`) istifadə olunur ki, bu da özbaşına istifadəçi yüksəldilməsinə səbəb ola bilər. Wazuh administratorları dərhal patched versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: Wazuh
FAQ2
Which versions of Wazuh are affected by CVE-2026-41424?
The vulnerability affects Wazuh platform versions from 4.9.0 to 4.10.4, as well as version 4.14.6.
What is the root cause of CVE-2026-41424?
The root cause is the incorrect usage of a parameter (`request.get("user")`) as current_user in API requests, instead of token-based user info.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.