# Metricbeat 8.19.10, 9.1.10, 9.2.4 Security Update (ESA-2026-01)

**URL:** https://discuss.elastic.co/t/metricbeat-8-19-10-9-1-10-9-2-4-security-update-esa-2026-01/384519
**Category:** Security Announcements
**Created:** [January 13, 2026, 8:42pm UTC](https://discuss.elastic.co/t/metricbeat-8-19-10-9-1-10-9-2-4-security-update-esa-2026-01/384519 "2026-01-13T20:42:47Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![ismisepaul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ismisepaul/32/102235_2.png) [@ismisepaul](https://discuss.elastic.co/u/ismisepaul)
#### Post date: [January 13, 2026, 8:42pm UTC](https://discuss.elastic.co/t/metricbeat-8-19-10-9-1-10-9-2-4-security-update-esa-2026-01/384519/1 "2026-01-13T20:42:48Z")

</div>

**Improper Input Validation in Metricbeat Leading to Denial of Service (ESA-2026-01)**

Improper Validation of Array Index (CWE-129) exists in Metricbeat can allow an attacker to cause a Denial of Service via Input Data Manipulation (CAPEC-153) using specially crafted, malformed payloads sent to the Graphite server metricset or Zookeeper server metricset. Additionally, Improper Input Validation (CWE-20) exists in the Prometheus helper module that can allow an attacker to cause a Denial of Service via Input Data Manipulation (CAPEC-153) using specially crafted, malformed metric data.

**Affected Versions:**

- 7.x: All versions
- 8.x: All versions from 8.0.0 up to and including 8.19.9
- 9.x:
  - All versions from 9.0.0 up to and including 9.1.9
  - All versions from 9.2.0 up to and including 9.2.3

**Solutions and Mitigations:**

The issue is resolved in version 8.19.10, 9.1.10, 9.2.4.

**Severity:** CVSSv3.1: Medium (6.5) - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H  
**CVE ID** : CVE-2026-0528  
**Problem Type:** Improper Validation of Array Index - CWE-20  
**Impact:** Overflow Buffers - CAPEC-100
