CVE-2026-28220 | Wazuh up to 4.14.4 Cluster Distributed API common.py as_wazuh_object rbac_permissions deserialization
A vulnerability was found in Wazuh up to 4.14.4 and classified as very critical. This vulnerability affects the function as_wazuh_object of the file framework/wazuh/core/cluster/common.py of the component Cluster Distributed API. Such manipulation of the argument rbac_permissions leads to deserialization.
This vulnerability is documented as CVE-2026-28220. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More