CVE-2026-54085 | Wazuh up to 4.14.6 Active Response route-null.c wpopenv srcip/dstuser argument injection

SecurityVulns

A vulnerability was found in Wazuh up to 4.14.6 and classified as problematic. The impacted element is the function wpopenv of the file route-null.c of the component Active Response. The manipulation of the argument srcip/dstuser results in argument injection.

This vulnerability is cataloged as CVE-2026-54085. The attack may be launched remotely. There is no exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More