Critical Remote Code Execution in Wazuh Cluster DAPI Protocol (CVE‑2026‑28220) Threatens SIEM Deployments
What It Is — A deserialization flaw in the Wazuh Cluster DAPI protocol (CVE‑2026‑28220) allows an attacker who can run low‑privileged code on a worker node to execute arbitrary commands as root on the master node.
Exploitability — CVSS 9.9 (Critical). Network‑adjacent attacker, low attack complexity, no user interaction required. No public exploit code yet, but the vulnerability is fully disclosed and can be weaponized quickly.
Affected Products — Wazuh (all versions prior to the 4.5.2 patch).
Why It Matters for Compliance & Audit Readiness
- SOC 2 CC6.1 (System Operations) requires documented, monitored controls over system changes; an unpatched deserialization bug demonstrates a gap in change‑management and code‑integrity controls.
- Continuous evidence of patch management is a core audit artifact; failure to remediate this flaw can be cited as a control deficiency during a SOC 2 audit.
- Enterprise buyers increasingly demand proof that security‑tooling (e.g., SIEMs) is itself hardened, making this vulnerability a red flag in vendor‑risk assessments.
Recommended Actions
- Apply the Wazuh 4.5.2 (or later) update that fixes CVE‑2026‑28220.
- Verify that the patch is reflected in your configuration‑management database and capture the version as audit evidence.
- Update your SOC 2 control mapping for “System Operations – Secure Configuration” and record remediation steps in your continuous‑compliance platform.
Source: Zero Day Initiative Advisory