CVE-2026-56699 CRITICAL

CVE-2026-56699: Wazuh Manager - NDJSON Injection in inventory_sync via Agent-Controlled DataValue.index

Vendor Wazuh
Product wazuh
Weakness CWE-74
Published July 15, 2026
Last update July 15, 2026

CVSS base score

10.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

What the vulnerability does

01Description

Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON operations. Attackers can smuggle delete, index, or update operations into bulk requests executed under the manager's admin credentials, enabling document deletion, alert tampering, and cross-agent SIEM state manipulation.

Key dates

02Disclosure timeline

July 15, 2026 CVE published
July 15, 2026 Record updated

Related vulnerabilities

04Related CVE