Security Advisory

CVE-2026-26932

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-02-26 16:59:55
Last updated 2026-02-26 18:28:12
Assigner elastic
State PUBLISHED

Description

Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker can send a specially crafted packet causing a Go runtime panic that terminates the Packetbeat process. This vulnerability requires the pgsql protocol to be explicitly enabled and configured to monitor traffic on the targeted port.