PT-2026-2848 · Elastic+1 · Packetbeat+1

Aisle Research

·

Published

2026-01-14

·

Updated

2026-05-12

·

CVE-2026-0529

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Packetbeat (affected versions not specified)
Description A flaw exists in Packetbeat’s MongoDB protocol parser related to improper validation of array index, which could allow for buffer overflows when processing specially crafted network traffic. An attacker can trigger this issue by sending a malformed payload to a monitored network interface where MongoDB protocol parsing is enabled. This requires the attacker to send a crafted payload.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Improper Validation of Array Index

Weakness Enumeration

Related Identifiers

BDU:2026-07213
CVE-2026-0529

Affected Products

Packetbeat
Red Os