4.14.8 Release notes - 23 September 2026
This section lists the changes in version 4.14.8. Every update of the Wazuh solution is cumulative and includes all enhancements and fixes from previous releases.
What's new
This release includes new features or enhancements as the following:
Wazuh agent
Resolved issues
This release resolves known issues as the following:
Wazuh manager
#37524 Fixed AES connection getting reset to blowfish on keystore rebuild.
#37764 Fixed a deadlock in
wazuh-analysisdthat stopped alert generation when the Active Response queue filled up.#37745 Restricted the upgrade commands accepted from the agent message channel in Analysisd.
#37838 Added destination path validation when deleting rule and decoder files.
#37901 Added source path validation when retrieving CDB list files.
#38214 Added path validation when listing and deleting CDB list files.
#37929 Fixed the
aws-s3wodle failing to parse configuration values that contain spaces, such asdiscard_regex,discard_field,aws_profile,aws_account_alias,pathandpath_suffix.#37850 Fixed
wazuh-dbexiting the worker thread instead of closing the peer socket when an oversized message is received.#37953 Improved SCA policy source validation to correctly enforce the
sca.remote_commandsrestriction.#38099 Added a minimum length check for legacy-format agent messages in
wazuh-remoted.#38085 Fixed a spurious
StarletteDeprecationWarningprinted byagent_upgradeat startup.#38412 Fixed a spurious
StarletteDeprecationWarningprinted bycluster_controland other framework CLI tools at startup.#38135 Fixed the API login attempt limit not being applied consistently under concurrent requests.
#38145 Fixed a heap buffer write in
wazuh-analysisdwhen generating FIM alerts by resizingfull_logbefore writing.#38180 Fixed password validation not being enforced for empty passwords in the
update_userAPI endpoint.#38193 Fixed API tokens for
run_asusers not being invalidated on logout or role revocation.#38239 Fixed a remote-command configuration validation bypass where upper- or mixed-case XML element names let command
localfileandwodleblocks pass theremote_commandsrestriction.
Wazuh agent
#37701 Prevented a race condition in
randombytesduring the initialization of the Windows RSA key container.#37769 Fixed missing macOS SSH authentication logs by adding the
sshd-sessionandsshd-authprocesses to the default Unified Logging query.#37441 Fixed the name, version and PyPI packages reported for Microsoft Store Python installations.
#39358 Fixed the FIM eBPF whodata provider swapping the reported
user_idandgroup_idin every event.#39335 Fixed FIM eBPF whodata attributing every file change to root when the kernel reports no loginuid.
Ruleset
#37434 Fixed Fortigate Decoder, malicious ioc rule and RHEL 8, 9, and 10 incorrect rpm check.
#37652 Fixed a typo in the
/etc/security/opasswdpermission check on Debian 10, Ubuntu 20.04 and Ubuntu 22.04 SCA rules.#37765 Fixed the LLMNR SCA check expected value on Windows Server 2016 and 2012.
#37770 Fixed a typo in the
/etc/shellspermission check on Debian 10, Ubuntu 20.04 and Ubuntu 22.04 SCA rules.#37950 Fixed MITRE ATT&CK tactic IDs being used instead of technique IDs in Microsoft Graph rules.
#38195 Fixed FortiAuth decoders mapping to incorrect fields.
Wazuh dashboard
#8763 Fixed a permission error in the Endpoints summary for a read-only user.
Changelogs
The repository changelogs provide more details about the changes.