CVE-2026-41424 | Wazuh up to 4.10.3/4.14.5 Security Controller security_controller.py remove_nones_to_dict User privileges management

SecurityVulns

A vulnerability classified as very critical has been found in Wazuh up to 4.10.3/4.14.5. Affected by this vulnerability is the function remove_nones_to_dict of the file api/api/controllers/security_controller.py of the component Security Controller. This manipulation of the argument User causes improper privilege management.

This vulnerability is tracked as CVE-2026-41424. The attack is possible to be carried out remotely. No exploit exists.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More