CVE-2026-74038 | Wazuh up to 4.14.5 Enrollment OS_IsValidName/delete_diff path traversal
A vulnerability labeled as critical has been found in Wazuh. The affected element is the function OS_IsValidName/delete_diff of the component Enrollment. Executing a manipulation can lead to path traversal.
This vulnerability is registered as CVE-2026-74038. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.VulDB Recent EntriesRead More