CVE-2026-48162 | Wazuh up to 4.14.5/5.0.0-beta2 DistributedAPI dapi.py DistributedAPI.send_tmp_file path traversal
A vulnerability, which was classified as very critical, was found in Wazuh up to 4.14.5/5.0.0-beta2. This vulnerability affects the function DistributedAPI.send_tmp_file of the file framework/wazuh/core/cluster/dapi/dapi.py of the component DistributedAPI. Executing a manipulation of the argument tmp_file can lead to path traversal.
This vulnerability is registered as CVE-2026-48162. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.VulDB Recent EntriesRead More