CVE-2025-54866: Wazuh

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.3.0 to before 4.13.0, a missing ACL on "C:\Program Files (x86)\ossec-agent\authd.pass" exposes the password to all "Authenticated Users" on the local machine. This issue has been patched in version 4.13.0.

Affected products

  • Wazuh Wazuh: from 4.3.0, before 4.13.0 (fixed in 4.13.0)

Published 2025-11-21. Last modified 2026-06-17.