CVE-2025-54866: Wazuh
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.3.0 to before 4.13.0, a missing ACL on "C:\Program Files (x86)\ossec-agent\authd.pass" exposes the password to all "Authenticated Users" on the local machine. This issue has been patched in version 4.13.0.
Affected products
- Wazuh Wazuh: from 4.3.0, before 4.13.0 (fixed in 4.13.0)
Published 2025-11-21. Last modified 2026-06-17.