6.5
/ 10
MEDIUM
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description
Improper Validation of Array Index (CWE-129) exists in Metricbeat can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed payloads sent to the Graphite server metricset or Zookeeper server metricset. Additionally, Improper Input Validation (CWE-20) exists in the Prometheus helper module that can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed metric data.
Basic Information
ID
CVE-2026-0528
Source
elastic
Published
Jan 13, 2026 at 21:02
Affected Product
Vendor
Elastic
Product
Metricbeat
Version
7.0.0
Affected Versions
Elastic Metricbeat 7.0.0
Elastic Metricbeat 8.0.0
Elastic Metricbeat 9.0.0
Elastic Metricbeat 9.2.0
Elastic Metricbeat 8.0.0
Elastic Metricbeat 9.0.0
Elastic Metricbeat 9.2.0