CVE-2026-61811 Overview
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. CVE-2026-61811 affects the _getattributes() function in src/os_xml/os_xml.c from version 3.8.0 through 4.14.6. The function recursively processes every XML attribute without a depth limit while allocating two large local buffers in each stack frame. An enrolled agent can submit a Windows EventChannel event containing an element with enough attributes to exhaust the analysisd worker-thread stack. The result is a segmentation fault that interrupts log ingestion across the Wazuh manager.
Critical Impact
An authenticated Wazuh agent can crash the analysisd worker thread on the manager, halting security event processing and creating a blind spot for downstream detections.
Affected Products
- Wazuh server versions 3.8.0 through 4.14.6
- Wazuh analysisd component processing Windows EventChannel events
- Deployments ingesting XML-formatted events via the os_xml parser
Discovery Timeline
- 2026-09-24 - CVE-2026-61811 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-61811
Vulnerability Analysis
The flaw is an uncontrolled recursion issue [CWE-674] in the Wazuh XML parser. The _getattributes() function in src/os_xml/os_xml.c calls itself for each attribute discovered on an XML element. Each invocation allocates two sizable local buffers on the stack, so the memory cost grows linearly with attribute count.
When an attacker-controlled event contains an element with a very large number of attributes, the recursion depth drives the thread stack past its limit. The analysisd worker thread segfaults and log ingestion stops until the service recovers. Because the condition is reproducible from a single malformed event, repeated submission produces a sustained denial-of-service against event processing.
Root Cause
The element-depth guard in _ReadElem() only limits nesting between elements. It does not account for the number of attributes attached to a single element, so _getattributes() has no bound on recursion depth. The combination of unbounded recursion and large per-frame stack allocations guarantees stack exhaustion well before any logical attribute limit is reached.
Attack Vector
Exploitation requires an enrolled Wazuh agent, which satisfies the low-privilege requirement in the scoring vector. The attacker crafts a Windows EventChannel event where a single XML element carries thousands of attributes. When analysisd parses the event, _getattributes() recurses into stack exhaustion and the worker thread dies.
// Patch: add explicit recursion depth tracking to _getattributes()
// Source: https://github.com/wazuh/wazuh/commit/2ac70941c5980a5dd24ad8a0f2be559f840e6a67
unsigned int parent, OS_XML *_lxml) __attribute__((nonnull));
static int _xml_fgetc(FILE *fp, OS_XML *_lxml) __attribute__((nonnull));
int _xml_sgetc(OS_XML *_lxml) __attribute__((nonnull));
-static int _getattributes(unsigned int parent, OS_XML *_lxml, bool flag_truncate, const int delim) __attribute__((nonnull));
+static int _getattributes(unsigned int parent, OS_XML *_lxml, bool flag_truncate, const int delim, unsigned int depth) __attribute__((nonnull));
static void xml_error(OS_XML *_lxml, const char *msg, ...) __attribute__((format(printf, 2, 3), nonnull));
// Patch: introduce hard cap on attribute recursion depth
// Source: https://github.com/wazuh/wazuh/commit/2ac70941c5980a5dd24ad8a0f2be559f840e6a67
#define LEOF -2
#define XML_MAXSIZE 20480
+#define XML_MAX_ATTR_DEPTH 48
#define XML_VARIABLE_MAXSIZE 256
Detection Methods for CVE-2026-61811
Indicators of Compromise
- Repeated analysisd segmentation faults in /var/ossec/logs/ossec.log or systemd journal entries for the Wazuh manager
- Core dumps attributed to the wazuh-analysisd process referencing _getattributes or os_xml frames
- Sudden gaps in alert ingestion correlated with agent reconnection events from a single enrolled endpoint
- Windows EventChannel payloads from an agent containing XML elements with an abnormally high attribute count
Detection Strategies
- Monitor analysisd process lifecycle for unexpected restarts and crash signatures linked to XML parsing
- Inspect ingested EventChannel events for element-to-attribute ratios that deviate from baseline Windows event schemas
- Correlate agent-side event submission volume with manager-side ingestion dips to identify a specific source agent
Monitoring Recommendations
- Alert on wazuh-analysisd service restarts or watchdog recoveries within short time windows
- Track per-agent event submission rates and flag outliers, especially from newly enrolled or recently reconfigured agents
- Capture and review core dumps from the manager host to confirm whether the crash signature matches the _getattributes() recursion pattern
How to Mitigate CVE-2026-61811
Immediate Actions Required
- Upgrade the Wazuh manager to version 4.14.7 or later, which caps attribute recursion depth via XML_MAX_ATTR_DEPTH
- Audit enrolled agents and revoke keys for any endpoints that are not strictly required to submit events
- Review recent analysisd crashes to identify whether the vulnerability has already been triggered in the environment
Patch Information
The fix is published in Wazuh Release v4.14.7 and tracked in GitHub Security Advisory GHSA-9wv5-7qwx-m9w5. The upstream code change is documented in Wazuh Pull Request #37147 and the corresponding commit 2ac70941. The patch adds a depth parameter to _getattributes() and enforces a hard limit of 48 recursive attribute parses per element.
Workarounds
- Restrict agent enrollment so only trusted endpoints can submit EventChannel data to the manager
- Place network controls between agents and the manager to rate-limit abnormal event submission volumes
- Enable automatic restart for wazuh-analysisd via systemd to shorten ingestion outages until patching completes
# Verify installed Wazuh manager version and upgrade on Debian/Ubuntu
/var/ossec/bin/wazuh-control info | grep WAZUH_VERSION
apt-get update && apt-get install --only-upgrade wazuh-manager=4.14.7-1
systemctl restart wazuh-manager
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.