CVE-2023-50260
Wazuh Agent vulnerability analysis and mitigation

Overview

The vulnerability (CVE-2023-50260) affects Wazuh's active response feature, specifically in versions 4.2.0 through 4.7.1. Discovered by a researcher working with Trend Micro Zero Day Initiative, this vulnerability was disclosed and patched in April 2024. The flaw exists within the host_deny script, which is part of Wazuh's active response mechanism that automatically triggers actions in response to alerts (Wazuh Advisory).

Technical details

The vulnerability stems from improper validation of JSON messages, specifically in the handling of IP address arguments within the host_deny script. The issue allows writing arbitrary strings to the hosts.deny file, which can lead to command execution. The vulnerability has been assigned a CVSS score of 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating its high severity. The flaw is classified as CWE-94, relating to improper control of generation of code (ZDI Advisory, Wazuh Advisory).

Impact

The vulnerability can result in system compromise, allowing remote attackers to gain control of vulnerable systems. When successfully exploited, it can lead to arbitrary command execution in the context of root, potentially affecting both server and agent hosts. The impact is particularly severe as it can lead to Local Privilege Escalation (LPE) on the server as root and Remote Code Execution (RCE) on agents as root (Fortiguard, Wazuh Advisory).

Exploitability

The vulnerability requires authentication to exploit. An attacker can trigger the active response by writing events either to the local execd queue on the server or to the ar queue which forwards the events to agents. The exploitation involves crafting specific JSON messages that can bypass the input validation mechanisms (ZDI Advisory, Wazuh Advisory).

Mitigation and workarounds

Wazuh has released version 4.7.2 to address this vulnerability. Organizations running affected versions (4.2.0 through 4.7.1) should upgrade to version 4.7.2 or later to mitigate the risk (Wazuh Advisory, Fortiguard).

Additional resources


SourceThis report was generated using AI

Related Wazuh Agent vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-25771HIGH7.5
  • Wazuh Agent logoWazuh Agent
  • cpe:2.3:a:wazuh:wazuh
NoYesMar 17, 2026
CVE-2026-25790HIGH7.2
  • Wazuh Agent logoWazuh Agent
  • cpe:2.3:a:wazuh:wazuh
NoYesMar 17, 2026
CVE-2026-25772HIGH7.2
  • Wazuh Agent logoWazuh Agent
  • cpe:2.3:a:wazuh:wazuh
NoYesMar 17, 2026
CVE-2026-32984MEDIUM5.3
  • Wazuh Agent logoWazuh Agent
  • cpe:2.3:a:wazuh:wazuh
NoYesMar 27, 2026
CVE-2023-7340MEDIUM5.3
  • Wazuh Agent logoWazuh Agent
  • cpe:2.3:a:wazuh:wazuh
NoYesMar 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management