CVE-2026-74039
Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allow_run_as enabled to exhaust CPU resources by submitting arbitrarily deeply nested JSON structures to the POST /security/user/authenticate/run_as endpoint. Attackers can repeatedly submit malformed auth_context bodies with unlimited nesting depth to cause the API framework to consume excessive CPU, denying service to all other API consumers.
- Affected products
- Wazuh
- CVSS 4.0
- 7.1 HIGH
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.3% (22th percentile)
- Weakness
- CWE-770, CWE-1333
- NVD status
- Received
- Published
- 2026-08-18
Fix
Upgrade the affected package to 4.14.7 or later.
No indexed exploits for CVE-2026-74039 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-74039 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.