SB2026022721 - Denial of service in Elastic Packetbeat



SB2026022721 - Denial of service in Elastic Packetbeat

Published: February 27, 2026

Security Bulletin ID SB2026022721
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Validation of Array Index (CVE-ID: CVE-2026-26932)

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to a boundary error in the PostgreSQL protocol parser when handling network traffic. A remote attacker can send specially crafted packets over the network and perform a denial of service attack.

Note, the vulnerability affects deployment s where the pgsql protocol type has been explicitly configured in packetbeat.yml and the Packetbeat instance is monitoring network traffic on an interface where PostgreSQL protocol traffic is present.


Remediation

Install update from vendor's website.