What is CVE-2026-45798?
A stack buffer overflow vulnerability has been found in the `compare_wazuh_versions()` function of the open-source security platform Wazuh, affecting versions 4.5.0 to 4.14.6 and 5.0.0-beta2. An attacker can control the 'V:' field during enrollment to overflow a 10-byte buffer with `strncpy()`. Users are advised to urgently update to a patched version.
Azərbaycanca: Sərbəst və açıq mənbə təhlükəsizlik platforması olan Wazuh-un 4.5.0-dən 4.14.6-ya qədər və 5.0.0-beta2 versiyalarında `compare_wazuh_versions()` funksiyasında stack buffer overflow zəifliyi aşkar edilib. Hücumçu enrollment zamanı 'V:' sahəsini idarə edərək 10 baytlıq bufferi aşa bilər. İstifadəçilərə dərhal zəiflik aradan qaldırılmış versiyalara yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
In which function was the CVE-2026-45798 vulnerability found in Wazuh?
The CVE-2026-45798 vulnerability was found in the `compare_wazuh_versions()` function.
How can an attacker exploit this stack buffer overflow vulnerability in Wazuh?
An attacker can control the 'V:' field during enrollment to overflow a 10-byte buffer using `strncpy()`.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.