CVE-2026-26932Disclosure(elasticsearch / packetbeat)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker can send a specially crafted packet causing a Go runtime panic that terminates the Packetbeat process. This vulnerability requires the pgsql protocol to be explicitly enabled and configured to monitor traffic on the targeted port.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-129

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • packetbeat

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-26); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
packetbeat

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-26: 1Mentions · 2026-03-13: 1Technical Details · 2026-02-26: 102-2603-13
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • DailyCVE@dailycve
    Disclosure

    🟠 Elastic Packetbeat, Denial of Service, #CVE-2026-26932 (Medium) https://dailycve.com/elastic-packetbeat-denial-of-service-cve-2026-26932-medium/

    Post summary

    The post links to a CVE‑2026‑26932 disclosure for Elastic Packetbeat describing a Denial of Service vulnerability, but it provides no PoC, exploit code, patch details, or technical specifics.

    0000029
    168 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26932 Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An at… https://www.cve.org/CVERecord?id=CVE-2026-26932

    Post summary

    The post announces CVE‑2026‑26932, detailing an array‑index validation flaw in Packetbeat’s PostgreSQL parser that can lead to DoS via input manipulation, with no PoC, exploit, or patch information provided.

    00000191
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appelasticsearchpacketbeat---

Explore more