THREAT OPS › Threat News › [NVD] CVE-2026-48024 (CRITICAL 9.1) — Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, cluster.unmerge_info() in framework/wazuh/core/cluster/cluster.py constructs paths from peer-controlled merge_type and name values in a merged sy
[NVD] CVE-2026-48024 (CRITICAL 9.1) — Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, cluster.unmerge_info() in framework/wazuh/core/cluster/cluster.py constructs paths from peer-controlled merge_type and name values in a merged sy
CVE-2026-48024 CVSS: 9.1 CRITICAL Published: 2026-08-19T17:18:51.093
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, cluster.unmerge_info() in framework/wazuh/core/cluster/cluster.py constructs paths from peer-controlled merge_type and name values in a merged synchronization archive. process_files_from_worker()
Indicators of compromise
- CVE-2026-48024cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-48024