CVE-2026-0528: Improper Input Validation in Metricbeat Leading to Denial of Service
Improper Validation of Array Index (CWE-129) exists in Metricbeat can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed payloads sent to the Graphite server metricset or Zookeeper server metricset. Additionally, Improper Input Validation (CWE-20) exists in the Prometheus helper module that can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed metric data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0528?
CVE-2026-0528 has a severity level that indicates a Denial of Service vulnerability due to improper input validation.
How do I fix CVE-2026-0528?
To fix CVE-2026-0528, ensure that you update to the latest version of Metricbeat or apply any relevant patches provided by the vendor.
What versions of Metricbeat are affected by CVE-2026-0528?
CVE-2026-0528 affects all versions of Metricbeat prior to the security update that addresses this vulnerability.
Can CVE-2026-0528 be exploited remotely?
Yes, CVE-2026-0528 can be exploited remotely by sending specially crafted malformed payloads to the Graphite server.
What impact does CVE-2026-0528 have on my systems?
CVE-2026-0528 can lead to a Denial of Service, rendering the affected Metricbeat service inoperable.