What is CVE-2026-67307?
A vulnerability in Wazuh 5.0.0-beta1 fails to validate the 'cluster_name' and 'cluster_node' fields in inventory-sync Start FlatBuffer messages, allowing a low-privileged agent to spoof cluster attributes. Users should upgrade to version 5.0.0-beta3 or later.
Azərbaycanca: Wazuh 5.0.0-beta1 versiyasında inventory-sync Start FlatBuffer mesajlarında 'cluster_name' və 'cluster_node' sahələrinin düzgün yoxlanılmaması zəifliyi aşkarlanıb. Bu, aşağı səlahiyyətli agentə saxta klaster atributları göndərməyə imkan verir. İstifadəçilərə 5.0.0-beta3 və ya daha yeni versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
Which fields are not properly validated in Wazuh 5.0.0-beta1, leading to the vulnerability?
The vulnerability arises because the 'cluster_name' and 'cluster_node' fields in inventory-sync Start FlatBuffer messages are not properly validated.
What can a low-privileged agent do by exploiting this vulnerability?
A low-privileged agent can spoof cluster attributes by sending forged cluster attributes.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.