boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-61802

Wazuh discloses cleartext cluster key to low-privilege API users via GET /cluster/local/config
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0070   51.6     —
AFFECTED
  Product  Versions               Fixed
  wazuh    >= 4.14.0, < 4.14.7 –  —
TIMELINE
  Jul 10  Reserved by GitHub_M
  Aug 27  Published (CNA: GitHub_M)
  Sep 15  EXPLOIT PUBLISHED — CVE-2026-61802 (wazuh). Public exploit reference added.
CWE-200, CWE-522 · CNA: GitHub_M · CVSS v3.1 · 2 references · NVD status: Analyzed

Description

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.14.0 through 4.14.6, a low-privilege API user can read the cleartext cluster key from a configuration endpoint that fails to redact it. The REST API provides a masking control, mask_sensitive_config, that redacts sensitive fields such as authd.pass and cluster.key from configuration responses for users who lack update-config permission, and every config-read endpoint carries this decorator except GET /cluster/local/config. That endpoint, backed by read_config_wrapper, is gated only by cluster:read and returns the local node's cluster configuration including the cleartext key, whereas its siblings return the same value masked. As a result, any account with the default readonly or cluster_readonly role, which is explicitly denied update-config precisely so it cannot view secrets, receives the real cluster key. Because the cluster key authenticates and encrypts traffic between cluster nodes, disclosing it to an unprivileged account provides the authentication precondition for the cluster-peer remote code execution chains established by prior advisories. This issue is fixed in version 4.14.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
July 10, 2026ReservedReserved by GitHub_M
August 27, 2026PublishedPublished (CNA: GitHub_M)
September 15, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-61802 (wazuh). Public exploit reference added.

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
wazuhwazuh—>= 4.14.0, < 4.14.7—

Weaknesses

CWE-200 · CWE-522

References (2)

Related

Authoritative record: CVE-2026-61802 at cve.org

Vendors: wazuh

Weaknesses: CWE-200 · CWE-522

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-61802 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.