CVE-2026-41424Wazuh · Wazuh
Vulnerability data via NVD (ingested)
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.9.0 until 4.10.4 and 4.14.6, PUT /security/users/{user_id} in api/api/controllers/security_controller.py passes request.get("user") instead of request.context['token_info']['sub'] as current_user. remove_nones_to_dict() removes the resulting None value, so the reserved-account protection in framework/wazuh/security.py cannot verify who is making the request. An authenticated user with the users_admin role can overwrite the password of protected administrator accounts with user IDs at or below 99, including the wazuh superuser, and gain full administrative control. This issue is fixed in versions 4.10.4 and 4.14.6.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-41424product:"Wazuh Wazuh"http.html:"Wazuh"More intel sources (5)
vuln:CVE-2026-41424vulnerabilities.cve_id: CVE-2026-41424CVE-2026-41424CVE-2026-41424"CVE-2026-41424" exploit -site:nvd.nist.gov