THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-49392 (MEDIUM 5.3) — Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.6.0 until 4.14.6 and 5.0.0-beta3, DB::getFile() and DB::searchFile() in src/syscheckd/src/db/src/file.cpp concatenate a monitored file path into SQLite row filters. On non-Windows

[NVD] CVE-2026-49392 (MEDIUM 5.3) — Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.6.0 until 4.14.6 and 5.0.0-beta3, DB::getFile() and DB::searchFile() in src/syscheckd/src/db/src/file.cpp concatenate a monitored file path into SQLite row filters. On non-Windows

mednvdPublished 2026-08-19

CVE-2026-49392 CVSS: 5.3 MEDIUM Published: 2026-08-19T17:18:53.770

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.6.0 until 4.14.6 and 5.0.0-beta3, DB::getFile() and DB::searchFile() in src/syscheckd/src/db/src/file.cpp concatenate a monitored file path into SQLite row filters. On non-Windows systems, FIMDBCreator::encodeString() does not esca

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-49392