Sploitus

CVE-2026-74039

No indexed exploits for CVE-2026-74039 yet

Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allow_run_as enabled to exhaust CPU resources by submitting arbitrarily deeply nested JSON structures to the POST /security/user/authenticate/run_as endpoint. Attackers can repeatedly submit malformed auth_context bodies with unlimited nesting depth to cause the API framework to consume excessive CPU, denying service to all other API consumers.

Affected products
Wazuh
CVSS 4.0
7.1 HIGH
CVSS 3.1
6.5 MEDIUM
EPSS
0.3% (22th percentile)
Weakness
CWE-770, CWE-1333
NVD status
Received
Published
2026-08-18

Fix

Upgrade the affected package to 4.14.7 or later.

CVE-2026-74039 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-74039 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-74039 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.