Metrics
Affected Vendors & Products
No advisories yet.
Solution
Upgrade the affected package to 4.14.7 or later.
Workaround
No workaround given by the vendor.
Tue, 18 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allow_run_as enabled to exhaust CPU resources by submitting arbitrarily deeply nested JSON structures to the POST /security/user/authenticate/run_as endpoint. Attackers can repeatedly submit malformed auth_context bodies with unlimited nesting depth to cause the API framework to consume excessive CPU, denying service to all other API consumers. | |
| Title | Wazuh 4.0.0 < 4.14.7 API DoS via Deeply Nested JSON auth_context | |
| Weaknesses | CWE-1333 CWE-770 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-18T18:45:38.241Z
Reserved: 2026-08-14T14:06:40.512Z
Link: CVE-2026-74039
Updated: 2026-08-18T18:45:33.903Z
Status : Received
Published: 2026-08-18T18:19:33.760
Modified: 2026-08-18T19:17:04.343
Link: CVE-2026-74039
No data.
OpenCVE Enrichment
Updated: 2026-08-18T18:30:16Z