CVE-2026-49441 | Wazuh up to 4.14.5/5.0.0-beta2 Cluster Master master.py process_files_from_worker file_path path traversal

SecurityVulns

A vulnerability classified as very critical was found in Wazuh up to 4.14.5/5.0.0-beta2. This issue affects the function process_files_from_worker of the file framework/wazuh/core/cluster/master.py of the component Cluster Master. Executing a manipulation of the argument file_path can lead to path traversal.

This vulnerability is tracked as CVE-2026-49441. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is advised.VulDB Recent EntriesRead More