CVE-2026-74039: Wazuh
Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.
Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allow_run_as enabled to exhaust CPU resources by submitting arbitrarily deeply nested JSON structures to the POST /security/user/authenticate/run_as endpoint. Attackers can repeatedly submit malformed auth_context bodies with unlimited nesting depth to cause the API framework to consume excessive CPU, denying service to all other API consumers.
Affected products
- Wazuh Wazuh: from 4.0.0, before 4.14.7 (fixed in 4.14.7); version 5.0.0 only
Published 2026-08-18. Last modified 2026-10-01.