CVE-2026-26933: Improper Validation of Array Index in Packetbeat Leading to Denial of Service

Published Mar 19, 2026
·
Updated

Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker with the ability to send specially crafted, malformed network packets to a monitored network interface can trigger out-of-bounds read operations, resulting in application crashes or resource exhaustion. This requires the attacker to be positioned on the same network segment as the Packetbeat deployment or to control traffic routed to monitored interfaces.

Affected Software

4 affected componentsFixes available
Elastic Packetbeat
go/github.com/elastic/beats/v7<7.0.0-alpha2.0.20260126223743-dec1b31111ec
7.0.0-alpha2.0.20260126223743-dec1b31111ec
Elasticsearch Packetbeat>=8.0.0<8.19.11
Elasticsearch Packetbeat>=9.0.0<9.2.5

Event History

Mar 19, 2026
CVE Published
via MITRE·05:08 PM
Data Sourced
via MITRE·05:08 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·06:31 PM
Data Sourced
via GitHub·06:31 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-26933?

CVE-2026-26933 is classified as a denial of service vulnerability due to improper validation of array indices in Packetbeat.

2

How do I fix CVE-2026-26933?

To remedy CVE-2026-26933, upgrade to Packetbeat version 7.0.0-alpha2.0.20260126223743-dec1b31111ec or newer.

3

What types of attacks can exploit CVE-2026-26933?

CVE-2026-26933 can be exploited through input data manipulation to achieve a denial of service.

4

Which versions of Packetbeat are affected by CVE-2026-26933?

Packetbeat versions between 8.0.0 and 8.19.11, as well as between 9.0.0 and 9.2.5, are affected by CVE-2026-26933.

5

Is it safe to use Packetbeat if it is not updated for CVE-2026-26933?

No, using an outdated version of Packetbeat that is vulnerable to CVE-2026-26933 poses a risk of denial of service attacks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203