CVE-2025-64483 Details
Description
Wazuh is a security detection, visibility, and compliance open source project. From version 4.9.0 to before 4.13.0, the Wazuh API – Agent Configuration in certain configurations allows authenticated users with read-only API roles to retrieve agent enrollment credentials through the /utils/configuration endpoint. These credentials can be used to register new agents within the same Wazuh tenant without requiring elevated permissions through the UI. This issue has been patched in version 4.13.0.
A vulnerability exists in the Wazuh API's Agent Configuration component, specifically in versions 4.9.0 prior to 4.13.0. In certain configurations, authenticated users with read-only API roles can access agent enrollment credentials through the /utils/configuration endpoint. These credentials, which include the enrollment password and DNS information, can be used to register new agents within the same Wazuh tenant without needing elevated permissions via the user interface. This issue has been patched in Wazuh version 4.13.0.
Users are advised to update to Wazuh version 4.13.0 or later. Future versions will include improvements to restrict access to enrollment credentials through role-based access control (RBAC). Additionally, enrollment credentials may be rotated or scoped to a specific time or IP window to reduce exposure.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 21, 2025CISA-ADP
Assessed Nov 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Wazuh | >= 4.9.0, < 4.13.0 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 6, 2026 | CVE Modified | [email protected] |
| Nov 21, 2025 | New CVE Received | [email protected] |
Volerion