← Vulnerability feed

Vulnerability record · CVE-2025-24016 · published 10 February 2025

CVE-2025-24016: Wazuh server unsafe deserialization allows remote code execution

Wazuh · Wazuh

Wazuh versions 4.4.0 through 4.9.0 deserialize DistributedAPI parameters with an unsafe helper (as_wazuh_object), letting an attacker who can inject an unsanitized dictionary into a DAPI request or response forge an unhandled exception and evaluate arbitrary Python code. Because Wazuh is a security monitoring platform, compromise of its server undermines the visibility and response capability it provides. Version 4.9.1 contains the fix.

9.9 CVSS 3.1 Critical CISA KEV since 10 Jun 2025 EPSS 94% · top 0.2% CWE-502 · Deserialization of untrusted data
9.9CVSS 3.1 base score
94%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an unsafe deserialization vulnerability allows for remote code execution on Wazuh servers. DistributedAPI parameters are a serialized as JSON and deserialized using `as_wazuh_object` (in `framework/wazuh/core/cluster/common.py`). If an attacker manages to inject an unsanitized dictionary in DAPI request/response, they can forge an unhandled exception (`__unhandled_exc__`) to evaluate arbitrary python code. The vulnerability can be triggered by anybody with API access (compromised dashboard or Wazuh servers in the cluster) or, in certain configurations, even by a compromised agent. Version 4.9.1 contains a fix.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.9, CISA KEV listing, very high EPSS probability and a vendor advisory tagged Exploit make this an actively targeted remote code execution flaw.

What it is

Wazuh versions 4.4.0 through 4.9.0 deserialize DistributedAPI parameters with an unsafe helper (as_wazuh_object), letting an attacker who can inject an unsanitized dictionary into a DAPI request or response forge an unhandled exception and evaluate arbitrary Python code. Because Wazuh is a security monitoring platform, compromise of its server undermines the visibility and response capability it provides. Version 4.9.1 contains the fix.

Impact

An attacker gains remote code execution on the Wazuh server, which can lead to full control of the monitoring infrastructure and the data and credentials it holds. The CVSS vector indicates high integrity and availability impact with scope change.

Attack surface

Reached over the network through the Wazuh API or cluster communication; the vector requires low privileges (PR:L) and no user interaction. The description states anyone with API access can trigger it, and in certain configurations a compromised agent can as well.

Exploitation

CVE-2025-24016 is listed in CISA KEV with a due date of 2025-07-01, and EPSS gives a 30-day probability of 0.9384 (99.84th percentile). The vendor advisory reference is tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade Wazuh to version 4.9.1 or later, which contains the fix.
  • If immediate upgrade is not possible, restrict network access to the Wazuh API and cluster ports to trusted hosts only.
  • Rotate credentials and API keys for Wazuh servers and dashboards, and review for signs of prior compromise.
  • Limit or disable agent enrollment and communication paths that could allow a compromised agent to reach DAPI, per vendor guidance.
  • Follow CISA KEV required actions and BOD 22-01 guidance for cloud-hosted instances.

Detection

  • Monitor Wazuh server and API logs for unexpected exceptions or references to __unhandled_exc__ in DAPI request or response handling.
  • Alert on unusual child processes or Python execution spawned by the Wazuh server or cluster daemons.
  • Review API access logs for anomalous or unexpected clients, especially from agent or dashboard sources.
  • Hunt for outbound network connections from Wazuh servers to unfamiliar destinations that could indicate post-exploitation activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-24016 to the Known Exploited Vulnerabilities catalog on 10 June 2025 as "Wazuh Server Deserialization of Untrusted Data Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 1 July 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-24016 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-30893Wazuh path traversal vulnerabilityWazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to before version 4.14.4, a path tra…EPSS 0.62%9.8CVE-2024-32038Wazuh heap-based buffer overflow vulnerabilityWazuh is a free and open source platform used for threat prevention, detection, and response. There is a buffer overflow hazard in wazuh-analysisd wh…EPSS 1.0%9.8CVE-2021-44079Wazuh command injection vulnerabilityIn the wazuh-slack active response script in Wazuh 4.2.x before 4.2.5, untrusted user agents are passed to a curl command line, potentially resulting…EPSS 3.4%9.5CVE-2024-1243Wazuh improper input validation vulnerabilityImproper input validation in the Wazuh agent for Windows prior to version 4.8.0 allows an attacker with control over the Wazuh server or agent key to…EPSS 0.64%9.1CVE-2026-61800Wazuh path traversal vulnerabilityWazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.4.0 through 4.14…EPSS 0.98%9.1CVE-2026-49441Wazuh vulnerabilityWazuh is a free and open source platform used for threat prevention, detection, and response. From 4.3.0 until 4.14.6 and 5.0.0-beta3, the non-merged…EPSS 0.77%9.1CVE-2026-48024Wazuh path traversal vulnerabilityWazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, cluster.unmerg…EPSS 0.78%9.1CVE-2026-48162Wazuh vulnerabilityWazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, DistributedAPI…EPSS 0.65%

Source: NIST National Vulnerability Database (record CVE-2025-24016), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.