CVE-2026-49392 | Wazuh up to 4.14.5/5.0.0-beta2 Syscheck file.cpp encodeString input validation
A vulnerability, which was classified as problematic, has been found in Wazuh up to 4.14.5/5.0.0-beta2. Impacted is the function DB::getFile/DB::searchFile/FIMDBCreator::encodeString of the file src/syscheckd/src/db/src/file.cpp of the component Syscheck. The manipulation leads to improper input validation.
This vulnerability is listed as CVE-2026-49392. The attack must be carried out locally. There is no available exploit.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More