CVE-2021-26814
HIGHWazuh 4.0.0-4.0.3 - Authenticated Remote Code Execution via /manager/files API
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2021-26814. PoCs published by WickdDavid, CYS4srl, paolorabbito.
AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2021-26814, which achieves remote code execution (RCE) on Wazuh Manager (v4.0.0-4.0.3) by leveraging API authentication, privilege escalation, and file overwrite techniques.
Description
Wazuh API in Wazuh from 4.0.0 to 4.0.3 allows authenticated users to execute arbitrary code with administrative privileges via /manager/files URI. An authenticated user to the service may exploit incomplete input validation on the /manager/files API to inject arbitrary code within the API service script.
Exploits (3)
This repository contains a functional Python exploit for CVE-2021-26814, which achieves remote code execution (RCE) on Wazuh Manager (v4.0.0-4.0.3) by leveraging API authentication, privilege escalation, and file overwrite techniques.
This repository contains a functional Python exploit for CVE-2021-26814, which achieves remote code execution (RCE) on Wazuh Manager (v4.0.0-4.0.3) by leveraging API authentication, privilege escalation, and file overwrite techniques. The exploit uses a reverse shell payload and requires valid credentials.
This repository contains a functional exploit for CVE-2021-26814, an authenticated RCE vulnerability in Wazuh v4.0.3. The exploit leverages path traversal and privilege escalation to overwrite a Python script with malicious code, achieving remote command execution.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H