Vulnerability record · CVE-2025-24016 · published 10 February 2025
CVE-2025-24016: Wazuh server unsafe deserialization allows remote code execution
Wazuh · Wazuh
Wazuh versions 4.4.0 through 4.9.0 deserialize DistributedAPI parameters with an unsafe helper (as_wazuh_object), letting an attacker who can inject an unsanitized dictionary into a DAPI request or response forge an unhandled exception and evaluate arbitrary Python code. Because Wazuh is a security monitoring platform, compromise of its server undermines the visibility and response capability it provides. Version 4.9.1 contains the fix.
Description
Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an unsafe deserialization vulnerability allows for remote code execution on Wazuh servers. DistributedAPI parameters are a serialized as JSON and deserialized using `as_wazuh_object` (in `framework/wazuh/core/cluster/common.py`). If an attacker manages to inject an unsanitized dictionary in DAPI request/response, they can forge an unhandled exception (`__unhandled_exc__`) to evaluate arbitrary python code. The vulnerability can be triggered by anybody with API access (compromised dashboard or Wazuh servers in the cluster) or, in certain configurations, even by a compromised agent. Version 4.9.1 contains a fix.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
Automated analysis
critical priorityCVSS 9.9, CISA KEV listing, very high EPSS probability and a vendor advisory tagged Exploit make this an actively targeted remote code execution flaw.
What it is
Wazuh versions 4.4.0 through 4.9.0 deserialize DistributedAPI parameters with an unsafe helper (as_wazuh_object), letting an attacker who can inject an unsanitized dictionary into a DAPI request or response forge an unhandled exception and evaluate arbitrary Python code. Because Wazuh is a security monitoring platform, compromise of its server undermines the visibility and response capability it provides. Version 4.9.1 contains the fix.
Impact
An attacker gains remote code execution on the Wazuh server, which can lead to full control of the monitoring infrastructure and the data and credentials it holds. The CVSS vector indicates high integrity and availability impact with scope change.
Attack surface
Reached over the network through the Wazuh API or cluster communication; the vector requires low privileges (PR:L) and no user interaction. The description states anyone with API access can trigger it, and in certain configurations a compromised agent can as well.
Exploitation
CVE-2025-24016 is listed in CISA KEV with a due date of 2025-07-01, and EPSS gives a 30-day probability of 0.9384 (99.84th percentile). The vendor advisory reference is tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade Wazuh to version 4.9.1 or later, which contains the fix.
- If immediate upgrade is not possible, restrict network access to the Wazuh API and cluster ports to trusted hosts only.
- Rotate credentials and API keys for Wazuh servers and dashboards, and review for signs of prior compromise.
- Limit or disable agent enrollment and communication paths that could allow a compromised agent to reach DAPI, per vendor guidance.
- Follow CISA KEV required actions and BOD 22-01 guidance for cloud-hosted instances.
Detection
- Monitor Wazuh server and API logs for unexpected exceptions or references to __unhandled_exc__ in DAPI request or response handling.
- Alert on unusual child processes or Python execution spawned by the Wazuh server or cluster daemons.
- Review API access logs for anomalous or unexpected clients, especially from agent or dashboard sources.
- Hunt for outbound network connections from Wazuh servers to unfamiliar destinations that could indicate post-exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-24016 to the Known Exploited Vulnerabilities catalog on 10 June 2025 as "Wazuh Server Deserialization of Untrusted Data Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 1 July 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/wazuh/wazuh/security/advisories/GHSA-hcrc-79hj-m3qh | ExploitVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24016 | US Government Resource |
Track CVE-2025-24016 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-24016), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.