CVE Database
/

CVE-2025-64483

Back to search

CVE-2025-64483

Published: Nov 21, 2025

Modified: Feb 6, 2026

PUBLISHED

Description

Wazuh is a security detection, visibility, and compliance open source project. From version 4.9.0 to before 4.13.0, the Wazuh API – Agent Configuration in certain configurations allows authenticated users with read-only API roles to retrieve agent enrollment credentials through the /utils/configuration endpoint. These credentials can be used to register new agents within the same Wazuh tenant without requiring elevated permissions through the UI. This issue has been patched in version 4.13.0.

VendorProductVersions

wazuh

wazuh-dashboard-plugins

affected
>= 4.9.0, < 4.13.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now