THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-45798 (HIGH 7.5) — Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.5.0 until 4.14.6 and 5.0.0-beta2, compare_wazuh_versions() in src/shared/version_op.c copies the attacker-controlled enrollment V: field into a 10-byte stack buffer with strncpy()

[NVD] CVE-2026-45798 (HIGH 7.5) — Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.5.0 until 4.14.6 and 5.0.0-beta2, compare_wazuh_versions() in src/shared/version_op.c copies the attacker-controlled enrollment V: field into a 10-byte stack buffer with strncpy()

mednvdPublished 2026-08-19

CVE-2026-45798 CVSS: 7.5 HIGH Published: 2026-08-19T17:18:49.730

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.5.0 until 4.14.6 and 5.0.0-beta2, compare_wazuh_versions() in src/shared/version_op.c copies the attacker-controlled enrollment V: field into a 10-byte stack buffer with strncpy() but does not explicitly terminate the buffer. The fun

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-45798