false positiv on cve-2026-9698

21 views
Skip to first unread message

No Data

unread,
Sep 16, 2026, 10:13:07 AM (6 days ago) Sep 16
to Wazuh | Mailing List
Hello,

CVE-2026-9698 on Red Hat Enterprise Linux 8 is a false positive. The CVE may be marked as both affected and fixed in the CTI, which can lead to an incorrect detection.


https://cti.wazuh.com/vulnerabilities/cves/CVE-2026-9698?affected%5Bvendor%5D=Red+Hat&affected%5Bplatform%5D=RHEL+8

https://access.redhat.com/security/cve/cve-2026-9698


installed version: 1.641-8.module+el8.10.0+24620+2953b6e4

wazuh version: 4.14.6



cve-2026-9698.png

Olamilekan Abdullateef Ajani

unread,
Sep 16, 2026, 11:55:43 AM (6 days ago) Sep 16
to Wazuh | Mailing List
Hello,

Thank you for reporting this. I checked the Red Hat advisories, and this does appear to be a false-positive detection.

Red Hat addressed CVE-2026-9698 for the perl-DBI:1.641 module in 1.641-5.module+el8.10.0+24438... through RHSA-2026:38901. Your installed version, 1.641-8.module+el8.10.0+24620+2953b6e4, is a newer Red Hat build published under RHSA-2026:52772.

The CTI page currently shows an unbounded "All affected" entry and a separate fixed threshold for the non-modular package, but it does not show the fixed threshold for the modular stream. That unbounded entry is likely causing the package to remain detected as vulnerable.

I will pass this along to the team internally for review. However, could you also confirm that the vulnerability is still shown as Active in the Wazuh dashboard and share the output of the following command?

rpm -q perl-DBI --qf '%{NAME}-%{EPOCHNUM}:%{VERSION}-%{RELEASE}.%{ARCH}\nModule: %{MODULARITYLABEL}\n'


Thanks again for sharing this.

No Data

unread,
Sep 21, 2026, 2:13:06 AM (yesterday) Sep 21
to Wazuh | Mailing List
  Looks like it’s been fixed.  
Reply all
Reply to author
Forward
0 new messages