Sploitus

CVE-2021-26814

7 known exploits for CVE-2021-26814

Wazuh API in Wazuh from 4.0.0 to 4.0.3 allows authenticated users to execute arbitrary code with administrative privileges via /manager/files URI. An authenticated user to the service may exploit incomplete input validation on the /manager/files API to inject arbitrary code within the API service script.

Affected products
Wazuh
Wazuh
≤ 4.0.3
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
8.7% (95th percentile)
Weakness
CWE-22
NVD status
Modified
Published
2021-03-06
CVE-2021-26814 at NVD
Authoritative description, scoring and affected products

7 known exploits for CVE-2021-26814

Proof-of-concept code and exploit modules indexed by Sploitus