What is CVE-2026-44901?
A critical vulnerability was found in Wazuh platform (CVE-2026-44901). It stems from the `AffectedItemsWazuhResult.merge()` function blindly trusting the `sort_casting` field in a cluster worker's JSON response, potentially leading to remote code execution. Organizations using Wazuh versions 4.0.0 through 4.14.6 and 5.0.0-beta2 should update to patched releases immediately.
Azərbaycanca: Wazuh platformasında kritik zəiflik aşkarlanıb (CVE-2026-44901). Bu, `AffectedItemsWazuhResult.merge()` funksiyasında cluster worker-dən gələn JSON cavabındakı `sort_casting` sahəsinə kor-koranə inamdan irəli gəlir və uzaqdan kod icrasına səbəb ola bilər. Wazuh 4.0.0-4.14.6 və 5.0.0-beta2 versiyalarını istifadə edən təşkilatlar dərhal yamalanmış versiyalara yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
What is the root cause of CVE-2026-44901 in the Wazuh platform?
The vulnerability stems from the `AffectedItemsWazuhResult.merge()` function blindly trusting the `sort_casting` field in a cluster worker's JSON response.
Which Wazuh versions are affected by CVE-2026-44901?
This vulnerability affects Wazuh versions 4.0.0 through 4.14.6 and 5.0.0-beta2.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.