CVE-2026-56699
CRITICALWazuh Manager - NDJSON Injection in inventory_sync via Agent-Controlled DataValue.index
Title source: cnaDescription
Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON operations. Attackers can smuggle delete, index, or update operations into bulk requests executed under the manager's admin credentials, enabling document deletion, alert tampering, and cross-agent SIEM state manipulation.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-ff9g-85jq-r3g3)
https://github.com/wazuh/wazuh/security/advisories/GHSA-ff9g-85jq-r3g3
Third Party Advisory third-party-advisory
VulnCheck Advisory: Wazuh Manager - NDJSON Injection in inventory_sync via Agent-Controlled DataValue.index
https://www.vulncheck.com/advisories/wazuh-manager-ndjson-injection-in-inventory-sync-via-agent-controlled-datavalue-index
Scores
CVSS v3
10.0
EPSS
0.0035
EPSS Percentile
27.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-74
Status
published
Products (2)
wazuh/wazuh
5.0.0-beta1 - 5.0.0-beta3
wazuh/wazuh
5.0.0-beta3
Published
Jul 15, 2026
Tracked Since
Jul 15, 2026