CVE-2026-67307 Details
Description
Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_node fields in inventory-sync Start FlatBuffer messages, while validating only the agentid against the authenticated agent identity. This allows a low-privileged enrolled agent to spoof cluster attribution in indexed inventory and vulnerability documents by forging wazuh.cluster.name values and influencing the document _id prefix, potentially tampering with inventory records or, in shared-indexer multi-cluster deployments, poisoning another cluster's records when numeric agent IDs collide.
A vulnerability in Wazuh version 5.0.0-beta1 allows low-privileged enrolled agents to spoof cluster attribution in indexed inventory and vulnerability documents. The issue arises because the inventory-sync Start FlatBuffer messages are not properly validated. While the manager verifies the agent ID against the authenticated agent identity, it fails to validate or override the cluster_name and cluster_node fields. This oversight enables agents to forge cluster information, influence document IDs, and potentially tamper with inventory records. In shared-indexer multi-cluster deployments, this could poison another cluster's records when numeric agent IDs collide.
Users can upgrade to Wazuh version 5.0.0-beta3, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/wazuh/wazuh/commit/b3dae02ec9ddcfd449cb61b4c76d180e3e43f79a | [email protected] | Patch |
| https://github.com/wazuh/wazuh/security/advisories/GHSA-jv5p-fhwh-9w55 | [email protected] | ExploitMitigationVendor Advisory |
| https://www.vulncheck.com/advisories/wazuh-before-beta3-cluster-attribution-spoofing-via-inventory-sync | [email protected] | ExploitPatchThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-345 | Insufficient Verification of Data Authenticity | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| wazuh wazuh | 5.0.0 beta1 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 1, 2026 | Initial Analysis | [email protected] |
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Aug 1, 2026 | New CVE Received | [email protected] |