Ad

CVE-2025-64483

MEDIUM CVSS 4.0: 5.3 EPSS 0.05%
Updated Feb 06, 2026
Wazuh
Parameter Value
CVSS 5.3 (MEDIUM)
Affected Versions before 4.13.0
Fixed In 4.13.0
Type CWE-284 (Improper Access Control)
Vendor Wazuh
Public PoC No

Wazuh is a security detection, visibility, and compliance open source project. From version 4.9.0 to before 4.13.0, the Wazuh API – Agent Configuration in certain configurations allows authenticated users with read-only API roles to retrieve agent enrollment credentials through the /utils/configuration endpoint. These credentials can be used to register new agents within the same Wazuh tenant without requiring elevated permissions through the UI.

This issue has been patched in version 4.13.0.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
Low
Partial disruption

CVSS Vector v4.0

Vulnerable Products

wazuh:wazuh-dashboard-plugins