製品・ソフトウェアに関する情報
Wazuh Inc.のWazuhにおけるパストラバーサルの脆弱性
Title Wazuh Inc.のWazuhにおけるパストラバーサルの脆弱性
Summary

Wazuhは、脅威の予防、検出、および対応に使用される無料かつオープンソースのプラットフォームです。バージョン4.0.0から4.10.3および4.11.0から4.14.4において、Wazuhマネージャの登録デーモン(authd)と同期デーモン(remoted)に論理的な欠陥があります。authdプロセスはエージェントが登録時にグループを選択できるようにしますが、「..」のようなパストラバーサルシーケンスをフィルタリングしません。一方、マネージャはwopendir()を使ってグループディレクトリをチェックしますが、「..」シーケンスは親ディレクトリ(/var/ossec/etc)を参照するため、検証を通過してしまいます。悪意のあるグループが受け入れられ、マネージャのグローバルデータベースに格納された後、remotedプロセスはこの未検証の値を使用してエージェント設定の同期用パスを構築します。結果として、client.keys、ossec.conf、内部証明書などの/var/ossec/etcにある機密ファイルがエージェントの共有設定ストリームに含まれ、攻撃者に漏洩してしまいます。この問題はバージョン4.10.4および4.14.5で修正されています。

Possible impacts ・当該ソフトウェアが扱う全ての情報が外部に漏れる可能性があります。 ・当該ソフトウェアが扱う情報について、書き換えは発生しません。 ・当該ソフトウェアは停止しません。 
Solution

ベンダ情報を参照して適切な対策を実施してください。

Publication Date July 17, 2026, midnight
Registration Date July 22, 2026, 10:20 a.m.
Last Update July 22, 2026, 10:20 a.m.
CVSS3.0 : 重要
Score 7.5
Vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected System
Wazuh Inc.
Wazuh 4.0.0 以上 4.10.4 未満
Wazuh 4.11.0 以上 4.14.5 未満
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
Change Log
No Changed Details Date of change
1 [2026年07月22日]
  掲載
July 22, 2026, 10:20 a.m.

NVD Vulnerability Information
CVE-2026-39359
Summary

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through 4.10.3 and 4.11.0 through 4.14.4, a logic flaw affects the Wazuh Manager's enrollment daemon (authd) and synchronization daemon (remoted). The authd process allows agents to select a group during enrollment but does not filter path traversal sequences such as "..." While the manager checks for the group directory using wopendir(), the ".." sequence references the parent directory (/var/ossec/etc), allowing it to pass validation. After the malicious group is accepted and stored in the manager's global database, the remoted process uses this unchecked value to build paths for agent configuration synchronization. As a result, sensitive files from /var/ossec/etc, such as client.keys, ossec.conf, and internal certificates, are included in the agent's shared configuration stream and exposed to the attacker. This issue has been fixed in versions 4.10.4 and 4.14.5.

Publication Date July 17, 2026, 9:16 a.m.
Registration Date July 18, 2026, 4:21 a.m.
Last Update July 20, 2026, 10:42 p.m.
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*:* 4.0.0 4.10.4
cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*:* 4.11.0 4.14.5
Related information, measures and tools
Common Vulnerabilities List