CVE-2025-15612
Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. Attackers with network access can perform man-in-the-middle attacks to intercept and modify downloaded dependencies or code during the build process, leading to remote code execution and supply chain compromise.
- Wazuh
- < 4.14.0
- CVSS 3.1
- 8.1 HIGH
- EPSS
- 0.2% (12th percentile)
- Weakness
- CWE-829, CWE-295
- NVD status
- Analyzed
- Published
- 2026-03-27
CVE-2025-15612 at NVD
No indexed exploits for CVE-2025-15612 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-15612 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.