THREAT OPS › Threat News › [NVD] CVE-2026-45798 (HIGH 7.5) — Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.5.0 until 4.14.6 and 5.0.0-beta2, compare_wazuh_versions() in src/shared/version_op.c copies the attacker-controlled enrollment V: field into a 10-byte stack buffer with strncpy()
[NVD] CVE-2026-45798 (HIGH 7.5) — Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.5.0 until 4.14.6 and 5.0.0-beta2, compare_wazuh_versions() in src/shared/version_op.c copies the attacker-controlled enrollment V: field into a 10-byte stack buffer with strncpy()
CVE-2026-45798 CVSS: 7.5 HIGH Published: 2026-08-19T17:18:49.730
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.5.0 until 4.14.6 and 5.0.0-beta2, compare_wazuh_versions() in src/shared/version_op.c copies the attacker-controlled enrollment V: field into a 10-byte stack buffer with strncpy() but does not explicitly terminate the buffer. The fun
Indicators of compromise
- CVE-2026-45798cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-45798