CVE-2026-48024 | Wazuh prior 4.14.6/5.0.0-beta3 Cluster cluster.py cluster.unmerge_info merge_type/name path traversal
A vulnerability identified as very critical has been detected in Wazuh. The impacted element is the function cluster.unmerge_info of the file framework/wazuh/core/cluster/cluster.py of the component Cluster. Performing a manipulation of the argument merge_type/name results in path traversal.
This vulnerability was named CVE-2026-48024. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.VulDB Recent EntriesRead More