Loading
Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. Attackers with network access can perform man-in-the-middle attacks to intercept and modify downloaded dependencies or code during the build process, leading to remote code execution and supply chain compromise.
Use CWE-295, Wazuh vendor hub and Wazuh product page to widen CVE-2025-15612 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-25770, CVE-2026-25769 and CVE-2025-15617 for nearby disclosures in the same product family.