THREAT OPS › Threat News › [NVD] CVE-2026-49392 (MEDIUM 5.3) — Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.6.0 until 4.14.6 and 5.0.0-beta3, DB::getFile() and DB::searchFile() in src/syscheckd/src/db/src/file.cpp concatenate a monitored file path into SQLite row filters. On non-Windows
[NVD] CVE-2026-49392 (MEDIUM 5.3) — Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.6.0 until 4.14.6 and 5.0.0-beta3, DB::getFile() and DB::searchFile() in src/syscheckd/src/db/src/file.cpp concatenate a monitored file path into SQLite row filters. On non-Windows
CVE-2026-49392 CVSS: 5.3 MEDIUM Published: 2026-08-19T17:18:53.770
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.6.0 until 4.14.6 and 5.0.0-beta3, DB::getFile() and DB::searchFile() in src/syscheckd/src/db/src/file.cpp concatenate a monitored file path into SQLite row filters. On non-Windows systems, FIMDBCreator::encodeString() does not esca
Indicators of compromise
- CVE-2026-49392cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-49392