What is CVE-2026-67308?
CVE-2026-67308 is a shell injection vulnerability in Wazuh GitHub Actions workflows. Attackers can execute arbitrary commands by submitting a pull request with a crafted VERSION.json file that injects shell metacharacters. Users should update workflows to the patched commit.
Azərbaycanca: CVE-2026-67308, Wazuh platformasının GitHub Actions iş axınlarında shell injection zəifliyidir. Təcavüzkar, xüsusi hazırlanmış VERSION.json faylı olan pull request təqdim edərək ixtiyari əmrlər icra edə bilər. İstifadəçilərə iş axınlarını təhlükəsiz commit-ə yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
What must an attacker do to exploit CVE-2026-67308?
Submit a pull request with a crafted VERSION.json file.
Which platform is affected by CVE-2026-67308?
Wazuh platform's GitHub Actions workflows.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.