moltenbit

I break software before someone worse does.

Security research and bug bounty, done the boring way: reported to the vendor, fixed, then written up here.

Latest writeups / 3

all writeups →

From the ledger / 5 of 39

full ledger →
CVE-2026-48024
Wazuh

merged-file header path traversal in cluster sync allows a cluster peer to write arbitrary files under WAZUH_PATH and reach root code execution

CVE-2026-48162
Wazuh

DAPI tmp_file path injection lets a cluster peer read arbitrary master files and forge REST API administrator tokens

CVE-2026-49441
Wazuh

peer-controlled metadata key in cluster sync allows arbitrary file writes under WAZUH_PATH and root code execution on the manager

CVE-2026-46647
GlobaLeaks

insufficient role enforcement allows non-admin internal users on the root or management tenant to read and modify network configuration

CVE-2026-46648
GlobaLeaks

incomplete tenant scoping lets a non-root tenant admin clear secondary escrow backup keys across all tenants