Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade the affected package to 4.14.7 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 18 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allow_run_as enabled to exhaust CPU resources by submitting arbitrarily deeply nested JSON structures to the POST /security/user/authenticate/run_as endpoint. Attackers can repeatedly submit malformed auth_context bodies with unlimited nesting depth to cause the API framework to consume excessive CPU, denying service to all other API consumers. | |
| Title | Wazuh 4.0.0 < 4.14.7 API DoS via Deeply Nested JSON auth_context | |
| Weaknesses | CWE-1333 CWE-770 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-18T17:26:12.871Z
Reserved: 2026-08-14T14:06:40.512Z
Link: CVE-2026-74039
No data.
Status : Received
Published: 2026-08-18T18:19:33.760
Modified: 2026-08-18T18:19:33.760
Link: CVE-2026-74039
No data.
OpenCVE Enrichment
Updated: 2026-08-18T18:30:16Z