CVE-2025-15617
Severity CVSS v4.0:
HIGH
Type:
CWE-522
Insufficiently Protected Credentials
Publication date:
27/03/2026
Last modified:
31/03/2026
Description
Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to extract the GITHUB_TOKEN from uploaded artifacts. Attackers can use the exposed token within a limited time window to perform unauthorized actions such as pushing malicious commits or altering release tags.
Impact
Base Score 4.0
8.30
Severity 4.0
HIGH
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:wazuh:wazuh:4.12.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



