6.5
/ 10
MEDIUM
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description
Improper Validation of Array Index (CWE-129) in Packetbeat’s MongoDB protocol parser can allow an attacker to cause Overflow Buffers (CAPEC-100) through specially crafted network traffic. This requires an attacker to send a malformed payload to a monitored network interface where MongoDB protocol parsing is enabled.
Basic Information
ID
CVE-2026-0529
Source
elastic
Published
Jan 14, 2026 at 10:09
Affected Product
Vendor
Elastic
Product
Packetbeat
Version
7.0.0
Affected Versions
Elastic Packetbeat 7.0.0
Elastic Packetbeat 8.0.0
Elastic Packetbeat 9.0.0
Elastic Packetbeat 9.2.0
Elastic Packetbeat 8.0.0
Elastic Packetbeat 9.0.0
Elastic Packetbeat 9.2.0