Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allow_run_as enabled to exhaust CPU resources by submitting arbitrarily deeply nested JSON structures to the POST /security/user/authenticate/run_as endpoint. Attackers can repeatedly submit malformed auth_context bodies with unlimited nesting depth to cause the API framework to consume excessive CPU, denying service to all other API consumers.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Upgrade the affected package to 4.14.7 or later.
Workaround
No workaround given by the vendor.
References
History
Tue, 18 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allow_run_as enabled to exhaust CPU resources by submitting arbitrarily deeply nested JSON structures to the POST /security/user/authenticate/run_as endpoint. Attackers can repeatedly submit malformed auth_context bodies with unlimited nesting depth to cause the API framework to consume excessive CPU, denying service to all other API consumers. | |
| Title | Wazuh 4.0.0 < 4.14.7 API DoS via Deeply Nested JSON auth_context | |
| Weaknesses | CWE-1333 CWE-770 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-18T17:26:12.871Z
Reserved: 2026-08-14T14:06:40.512Z
Link: CVE-2026-74039
No data.
Status : Received
Published: 2026-08-18T18:19:33.760
Modified: 2026-08-18T18:19:33.760
Link: CVE-2026-74039
No data.
OpenCVE Enrichment
Updated: 2026-08-18T18:30:16Z