CVE-2026-56401
Wazuh Wazuh, wazuh
Wazuh wazuh-modulesd before 5.0.0-beta3 contains a null pointer dereference vulnerability in inventory_sync FlatBuffer DataValue handling. An enrolled agent can send a verifier-valid DataValue message omitting the optional id field, causing wazuh-modulesd to crash when dereferencing data->id()->string_view() without null validation, resulting in denial of service.
- CVSS
- 7.1
- EPSS
- 0.33% 24.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.08