ZeroHour

CVE-2026-67307

PoC ×2moderate

Cluster Attribution Spoofing in Wazuh Inventory Sync (CVSS 4.0: 7.0)

CVSS 4.0
7.0 high
EPSS
<1%p9
Published
()
Modified
AI analysis

Wazuh 5.0.0-beta1 fails to validate or override the cluster_name and cluster_node fields in inventory-sync Start FlatBuffer messages, checking only that the agentid matches the authenticated agent identity (CWE-345, insufficient verification of data authenticity). A low-privileged enrolled agent can exploit this by sending crafted inventory-sync messages that forge the wazuh.cluster.name value and influence the document _id prefix in indexed inventory and vulnerability documents. This lets the attacker tamper with inventory records and, in shared-indexer multi-cluster deployments, poison another cluster's records when numeric agent IDs collide; CVSS 4.0 scores the issue 7.0 (High) with high integrity impact on the affected and subsequent systems. Deployments running Wazuh 5.0.0 prerelease builds before 5.0.0-beta3 are affected, with multi-cluster environments sharing an indexer facing the greatest risk. No in-the-wild exploitation is currently known: public proof-of-concept references exist (VulnCheck and a GitHub security advisory), EPSS is 0.2% (9th percentile), and the issue is not in CISA KEV.

What to do: Upgrade to Wazuh 5.0.0-beta3 or later. In the meantime, especially in shared-indexer multi-cluster deployments, review indexed inventory and vulnerability documents for unexpected wazuh.cluster.name values or _id prefixes and check for records overwritten via numeric agent ID collisions across clusters. Restrict agent enrollment to trusted hosts and monitor inventory-sync traffic for anomalous cluster field values until patched.

Affected
Wazuh5.0.0 prerelease builds before 5.0.0-beta3 (confirmed affected: 5.0.0-beta1); fixed in 5.0.0-beta3
Estimated exposure
moderate≈ a few thousand deployments (Wazuh's 5.0.0 beta-channel installs) — Wazuh has a very large open-source SIEM/XDR install base, but this flaw is confined to 5.0.0 prerelease (beta) builds, so deployment patterns suggest only early-adopter beta deployments — likely low thousands — are affected.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_node fields in inventory-sync Start FlatBuffer messages, while validating only the agentid against the authenticated agent identity. This allows a low-privileged enrolled agent to spoof cluster attribution in indexed inventory and vulnerability documents by forging wazuh.cluster.name values and influencing the document _id prefix, potentially tampering with inventory records or, in shared-indexer multi-cluster deployments, poisoning another cluster's records when numeric agent IDs collide.

Vendors
wazuh
Products
wazuh
Weakness
CWE-345
Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.