4.14.7 Release notes - 29 July 2026

This section lists the changes in version 4.14.7. Every update of the Wazuh solution is cumulative and includes all enhancements and fixes from previous releases.

What's new

This release includes new features or enhancements as the following:

Wazuh manager

  • #37035 Removed deprecated wazuh-dbd daemon and database_output configuration.

Other

  • #37361 Updated aiohttp, cryptography, PyJWT, python-multipart, and starlette Python dependencies.

Wazuh dashboard

  • #8713 Added sanitization in the markdown component.

Resolved issues

This release resolves known issues as the following:

Wazuh manager

  • #37280 Improved cluster payload buffer allocation strategy.

  • #37119 Improved cluster archive decompression limits.

  • #36998 Improved cluster worker file path validation.

  • #37034 Improved API authentication stability with bounded thread pools, regex timeouts, and payload size limits.

Wazuh agent

  • #36791 Fixed AWS SQS subscriber wodle resolving the wrong AWS account for cross-account iam_role_arn configurations.

  • #36338 Fixed agent keepalive scheduling after a system clock rollback causing false Disconnected status.

  • #37014 Fixed eBPF FIM whodata dropping file events on older kernels such as Amazon Linux 2 and 2023.

  • #37023 Fixed eBPF FIM whodata missing file move/rename events into monitored folders.

  • #36730 Added IP address validation to the ip-customblock active response to prevent malformed input in file path operations.

  • #37245 Added a null check for inode and device fields in the FIM whodata event handler.

RESTful API

  • #37323 Fixed TypeError when sorting agents by version with empty version strings.

  • #37039 Improved sensitive data masking in cluster configuration endpoint.

Ruleset

  • #37385 Fixed multiple Debian, Ubuntu, and Windows SCA checks generating incorrect results.

  • #36361 Fixed a typo in the SELinux SCA check causing false failures on CentOS 8, 9, and 10 systems configured as permissive.

  • #36396 Fixed the AlmaLinux 9 and 10 bootloader permissions SCA check regex and optional file handling.

  • #36795 Fixed the /etc/gshadow- permissions SCA check always failing due to an incorrect all condition.

  • #36783 Fixed a macOS SCA PolicyBanner check false failure by wrapping the command in sh -c for glob expansion.

Changelogs

The repository changelogs provide more details about the changes.

Product repositories

Auxiliary repositories