CVE-2026-67307
Received Received - Intake

Cluster Name Spoofing in Wazuh 5.0.0-beta1

Vulnerability report for CVE-2026-67307, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-01

Last updated on: 2026-08-01

Assigner: VulnCheck

Description

Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_node fields in inventory-sync Start FlatBuffer messages, while validating only the agentid against the authenticated agent identity. This allows a low-privileged enrolled agent to spoof cluster attribution in indexed inventory and vulnerability documents by forging wazuh.cluster.name values and influencing the document _id prefix, potentially tampering with inventory records or, in shared-indexer multi-cluster deployments, poisoning another cluster's records when numeric agent IDs collide.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-01
Last Modified
2026-08-01
Generated
2026-08-01
AI Q&A
2026-08-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wazuh wazuh to 5.0.0-beta3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Wazuh 5.0.0-beta1 allows a low-privileged enrolled agent to forge cluster attribution in inventory and vulnerability documents by manipulating the cluster_name and cluster_node fields in Start FlatBuffer messages. The system only validates the agentid against the authenticated agent identity, enabling spoofing of cluster details and potential tampering with inventory records.

Impact Analysis

This vulnerability could allow an attacker to alter inventory records or poison another cluster's records in shared-indexer multi-cluster deployments. This may lead to incorrect data being stored or processed, potentially causing operational disruptions or misleading security assessments.

Mitigation Strategies

Upgrade Wazuh to version 5.0.0-beta3 or later to address the validation issue in cluster_name and cluster_node fields.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67307. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart