CVE-2026-56699 is a critical vulnerability affecting Wazuh Manager versions prior to 5.0.0-beta3 and OpenSearch platforms. The flaw arises from improper escaping of the DataValue.index field when constructing bulk requests, enabling enrolled agents to inject arbitrary NDJSON operations. Attackers can exploit this to smuggle malicious delete, index, or update commands into bulk requests executed under the manager's administrative credentials. This allows unauthorized deletion of documents, modification of alerts, and manipulation of cross-agent SIEM states, compromising data integrity and operational visibility. The vulnerability carries a CVSS score of 10.0, reflecting its severe impact on confidentiality, integrity, and availability. Organizations using affected versions of Wazuh Manager or OpenSearch are strongly advised to upgrade to 5.0.0-beta3 or later to mitigate this risk. Immediate action is required to prevent potential exploitation, as no workarounds are available for this privilege escalation and data manipulation vulnerability.