CVE-2025-64483

Wazuh is a security detection, visibility, and compliance open source project. From version 4.9.0 to before 4.13.0, the Wazuh API – Agent Configuration in certain configurations allows authenticated users with read-only API roles to retrieve agent enrollment credentials through the /utils/configuration endpoint. These credentials can be used to register new agents within the same Wazuh tenant without requiring elevated permissions through the UI. This issue has been patched in version 4.13.0.
CVSS

No CVSS.

Configurations

No configuration.

History

21 Nov 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-21 18:15

Updated : 2025-11-25 22:16


NVD link : CVE-2025-64483

Mitre link : CVE-2025-64483

CVE.ORG link : CVE-2025-64483


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control