4.14.8 Release notes - 23 September 2026

This section lists the changes in version 4.14.8. Every update of the Wazuh solution is cumulative and includes all enhancements and fixes from previous releases.

What's new

This release includes new features or enhancements as the following:

Wazuh agent

  • #37725 Improved SCA policy YAML parsing to bound memory usage on deeply nested policies.

  • #32467 Added audit_uid, audit_name, audit_gid, and audit_group_name fields to FIM whodata alerts generated by the eBPF provider.

Resolved issues

This release resolves known issues as the following:

Wazuh manager

  • #37524 Fixed AES connection getting reset to blowfish on keystore rebuild.

  • #37764 Fixed a deadlock in wazuh-analysisd that stopped alert generation when the Active Response queue filled up.

  • #37745 Restricted the upgrade commands accepted from the agent message channel in Analysisd.

  • #37838 Added destination path validation when deleting rule and decoder files.

  • #37901 Added source path validation when retrieving CDB list files.

  • #38214 Added path validation when listing and deleting CDB list files.

  • #37929 Fixed the aws-s3 wodle failing to parse configuration values that contain spaces, such as discard_regex, discard_field, aws_profile, aws_account_alias, path and path_suffix.

  • #37850 Fixed wazuh-db exiting the worker thread instead of closing the peer socket when an oversized message is received.

  • #37953 Improved SCA policy source validation to correctly enforce the sca.remote_commands restriction.

  • #38099 Added a minimum length check for legacy-format agent messages in wazuh-remoted.

  • #38085 Fixed a spurious StarletteDeprecationWarning printed by agent_upgrade at startup.

  • #38412 Fixed a spurious StarletteDeprecationWarning printed by cluster_control and other framework CLI tools at startup.

  • #38135 Fixed the API login attempt limit not being applied consistently under concurrent requests.

  • #38145 Fixed a heap buffer write in wazuh-analysisd when generating FIM alerts by resizing full_log before writing.

  • #38180 Fixed password validation not being enforced for empty passwords in the update_user API endpoint.

  • #38193 Fixed API tokens for run_as users not being invalidated on logout or role revocation.

  • #38239 Fixed a remote-command configuration validation bypass where upper- or mixed-case XML element names let command localfile and wodle blocks pass the remote_commands restriction.

Wazuh agent

  • #37701 Prevented a race condition in randombytes during the initialization of the Windows RSA key container.

  • #37769 Fixed missing macOS SSH authentication logs by adding the sshd-session and sshd-auth processes to the default Unified Logging query.

  • #37441 Fixed the name, version and PyPI packages reported for Microsoft Store Python installations.

  • #39358 Fixed the FIM eBPF whodata provider swapping the reported user_id and group_id in every event.

  • #39335 Fixed FIM eBPF whodata attributing every file change to root when the kernel reports no loginuid.

Ruleset

  • #37434 Fixed Fortigate Decoder, malicious ioc rule and RHEL 8, 9, and 10 incorrect rpm check.

  • #37652 Fixed a typo in the /etc/security/opasswd permission check on Debian 10, Ubuntu 20.04 and Ubuntu 22.04 SCA rules.

  • #37765 Fixed the LLMNR SCA check expected value on Windows Server 2016 and 2012.

  • #37770 Fixed a typo in the /etc/shells permission check on Debian 10, Ubuntu 20.04 and Ubuntu 22.04 SCA rules.

  • #37950 Fixed MITRE ATT&CK tactic IDs being used instead of technique IDs in Microsoft Graph rules.

  • #38195 Fixed FortiAuth decoders mapping to incorrect fields.

Wazuh dashboard

  • #8763 Fixed a permission error in the Endpoints summary for a read-only user.

Changelogs

The repository changelogs provide more details about the changes.

Product repositories

Auxiliary repositories