CVE Explorer
CVE-2026-39359
Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through 4.10.3 and 4.11.0 through 4.14.4, a logic flaw affects the Wazuh Manager's enrollment daemon (authd) and synchronization daemon (remoted). The authd process allows agents to select a group during enrollment but does not filter path traversal sequences such as "..." While the manager checks for the group directory using wopendir(), the ".." sequence references the parent directo
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"wazuh","vendor":"wazuh","versions":[{"status":"affected","version":">= 4.0.0, < 4.10.4"},{"status":"affected","version":">= 4.11.0, < 4.14.5"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f23aa6965515087a286800ed5038b387440a9085b5da0e2733a3c82b888dc5cd · sha256:b9c80e6d0b1cdcca… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f23aa6965515087a286800ed5038b387440a9085b5da0e2733a3c82b888dc5cd · sha256:b9c80e6d0b1cdcca… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f23aa6965515087a286800ed5038b387440a9085b5da0e2733a3c82b888dc5cd · sha256:b9c80e6d0b1cdcca… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["exploit"],"url":"https://github.com/wazuh/wazuh/security/advisories/GHSA-6q95-fcwc-4h44"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f23aa6965515087a286800ed5038b387440a9085b5da0e2733a3c82b888dc5cd · sha256:b9c80e6d0b1cdcca… · /containers/adp/0/references/0
{"name":"https://github.com/wazuh/wazuh/security/advisories/GHSA-6q95-fcwc-4h44","tags":["x_refsource_CONFIRM"],"url":"https://github.com/wazuh/wazuh/security/advisories/GHSA-6q95-fcwc-4h44"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f23aa6965515087a286800ed5038b387440a9085b5da0e2733a3c82b888dc5cd · sha256:b9c80e6d0b1cdcca… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.