SB2026022721 - Denial of service in Elastic Packetbeat
Published: February 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Validation of Array Index (CVE-ID: CVE-2026-26932)
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to a boundary error in the PostgreSQL protocol parser when handling network traffic. A remote attacker can send specially crafted packets over the network and perform a denial of service attack.
Note, the vulnerability affects deployment s where the pgsql protocol type has been explicitly configured in packetbeat.yml and the Packetbeat instance is monitoring network traffic on an interface where PostgreSQL protocol traffic is present.
Remediation
Install update from vendor's website.