CVE-2026-56699 Details
Description
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Per Wazuh's Security Policy, vulnerabilities affecting only non-GA versions are not eligible for a CVE ID.
A critical NDJSON injection vulnerability has been identified in Wazuh Manager versions 5.0.0-beta1 prior to 5.0.0-beta3. The issue arises in the 'inventory_sync' subsystem, where the 'DataValue.index' field is not properly escaped before being sent in OpenSearch bulk requests. This flaw allows enrolled agents to inject arbitrary NDJSON operations, such as delete, index, or update actions, into requests that are executed under the manager's admin credentials. As a result, attackers could delete documents, tamper with alerts, and manipulate SIEM states across different agents.
Users are advised to update to Wazuh Manager version 5.0.0-beta3 or later. Additionally, the vulnerability can be addressed by escaping the 'DataValue.index' field at the sink and validating index names at the boundary where agent data is received.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
No references are available for this CVE.
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 6, 2026 | CVE Rejected | [email protected] |
| Aug 6, 2026 | CVE Modified | [email protected] |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | New CVE Received | [email protected] |