Wazuh Cluster DAPI Privilege Escalation Vulnerability via Unsafe Deserialization and RBAC Injection

Vulnerability

A vulnerability in Wazuh's Cluster Distributed API (DAPI) prior to version 4.14.5 allows authenticated cluster peers to exploit unsafe deserialization of JSON objects. The master node can be manipulated to execute attacker-controlled functions within a compromised Role-Based Access Control (RBAC) context. This exploitation enables unauthorized administrative actions, such as arbitrary file modifications, creation of API users, and alterations to the security configuration, potentially leading to a complete compromise of the Wazuh manager.

Impact

Exploitation of this vulnerability allows for unauthorized execution of privileged functions on the Wazuh master node, bypassing standard RBAC controls. This could result in unauthorized changes to critical configurations, creation or modification of user accounts, and manipulation of the overall security posture, with the potential for broader impacts across the Wazuh cluster.

Reproduction

The vulnerability can be reproduced by deploying a Wazuh cluster with a master node accessible on the default cluster port. After obtaining the shared cluster key, a crafted DAPI payload can be sent to the master node, exploiting the deserialization of callables and the injection of a manipulated RBAC context. This can be done using a Python script that automates the process, including the necessary authentication and payload crafting.

Remediation

Users should upgrade to Wazuh version 4.14.5 or later, where this vulnerability has been addressed.

Added: Jul 20, 2026, 5:17 PM
Updated: Jul 20, 2026, 5:17 PM

Vulnerability Rating

Custom Algorithm
spread
6.2
impact
7.5
exploitability
4.2
remediation
7.7
relevance
10.0
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.