CVE-2026-32984
Severity CVSS v4.0:
MEDIUM
Type:
CWE-125
Out-of-bounds Read
Publication date:
27/03/2026
Last modified:
31/03/2026
Description
Wazuh authd contains a heap-buffer overflow vulnerability that allows attackers to cause memory corruption and malformed heap data by sending specially crafted input. Attackers can exploit this vulnerability to trigger a denial of service condition, resulting in low availability impact to the authentication daemon.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM
Base Score 3.x
3.50
Severity 3.x
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*:* | 3.5.0 (including) | |
| cpe:2.3:a:wazuh:wazuh:4.3.10:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



