CVE-2025-15612

Severity CVSS v4.0:
MEDIUM
Type:
CWE-295 Improper Certificate Validation
Publication date:
27/03/2026
Last modified:
08/04/2026

Description

Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. Attackers with network access can perform man-in-the-middle attacks to intercept and modify downloaded dependencies or code during the build process, leading to remote code execution and supply chain compromise.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*:* 4.1.3 (including) 4.14.0 (excluding)