What is CVE-2026-44255?
An authentication flaw was discovered in Wazuh platform. When a login attempt is made with a non-existent username, the password check is skipped, potentially creating a security risk. Versions prior to 4.14.6 and 5.0.0-beta2 are affected, and an update is recommended.
Azərbaycanca: Wazuh platformasında autentifikasiya zəifliyi aşkarlanıb. Mövcud olmayan istifadəçi adı ilə daxil olmaq cəhdi zamanı parol yoxlanışı atlanır və bu, potensial təhlükəsizlik riski yaradır. 4.14.6 və 5.0.0-beta2 versiyalarından əvvəlki versiyalar təsirlənir, yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: Wazuh
FAQ2
How can CVE-2026-44255 be exploited in Wazuh platform?
When a login attempt is made with a non-existent username, the password check is skipped, bypassing the authentication mechanism.
Which versions of Wazuh are affected by CVE-2026-44255?
All versions prior to 4.14.6 and 5.0.0-beta2 are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.