Horizon Alert
Summary of the vulnerability and why it matters
This advisory addresses a critical vulnerability within the Wazuh platform, specifically impacting its Cluster Distributed API. If exploited, an authenticated actor could gain administrative control of the master node, enabling actions such as arbitrary file writes, user creation, and modification of security configurations. The primary concern is confirming if your environment utilizes Wazuh in a clustered configuration where this API is accessible.
- A flaw allows unauthorized administrative control.
- Matters if you use Wazuh's clustered features.
- Confirm Wazuh cluster relevance and exposure.
Attack Path
How an attacker could exploit the issue
An attacker who can authenticate to the Wazuh cluster channel can cause the master node to deserialize and execute arbitrary code. This is achieved by sending a crafted DAPI request that includes a specific RBAC permission, allowing the attacker to bypass authorization checks and execute privileged administrative actions. The vulnerability can be chained to achieve full manager compromise.
- Requires authenticated access to the cluster channel.
- Triggered by deserializing attacker-controlled callable.
- Risk of arbitrary code execution and full compromise.
Live Threat
Current exploitation, exposure, and threat context
A Wazuh master node could allow a cluster peer to deserialize and execute attacker-controlled code, potentially leading to administrative actions. This could affect system data and sensitive information when supported by the advisory and authentication using the shared cluster key.
- Master node administrative actions at risk.
- Malicious code executed via API.
- Full manager compromise may occur.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Wazuh platform's Cluster Distributed API (DAPI) is susceptible to a critical vulnerability if not updated. This issue impacts the master node and requires an actor with authenticated access to the cluster channel, typically a cluster peer. The first practical step involves identifying all Wazuh cluster instances, confirming their reachability and business criticality, and locating the accountable Wazuh platform or infrastructure owner for remediation planning.
- Owner: Wazuh platform/infrastructure team.
- Verify: Cluster communication reachability and criticality.
- Action: Plan and coordinate Wazuh upgrade.