CVE-2026-32984: Wazuh

Low severity, CVSS 3.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Wazuh authd contains a heap-buffer overflow vulnerability that allows attackers to cause memory corruption and malformed heap data by sending specially crafted input. Attackers can exploit this vulnerability to trigger a denial of service condition, resulting in low impact on the availability of the authentication daemon.

Affected products

  • Wazuh Wazuh: up to and including 3.5.0; version 4.3.10 only

Published 2026-03-27. Last modified 2026-06-17.