# Metricbeat 8.19.13, 9.2.5 Security Update (ESA-2026-09)

**URL:** <https://discuss.elastic.co/t/metricbeat-8-19-13-9-2-5-security-update-esa-2026-09/385532>\
**Category:** Security Announcements\
**Created:** [March 19, 2026, 4:54pm UTC](https://discuss.elastic.co/t/metricbeat-8-19-13-9-2-5-security-update-esa-2026-09/385532 "2026-03-19T16:54:15Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![ismisepaul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ismisepaul/32/102235_2.png) [@ismisepaul](https://discuss.elastic.co/u/ismisepaul)\
**Post date:** [March 19, 2026, 4:54pm UTC](https://discuss.elastic.co/t/metricbeat-8-19-13-9-2-5-security-update-esa-2026-09/385532/1 "2026-03-19T16:54:15Z")

</div>

**Memory Allocation with Excessive Size Value in Metricbeat Leading to Denial of Service**

Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote\_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).

**Affected Versions:**

- 8.x: All versions from 8.0.0 up to and including 8.19.12
- 9.x: All versions from 9.0.0 up to and including 9.2.4

**Affected Configurations:**  
The Prometheus `remote_write` module is not enabled by default in Metricbeat, so this issue only affects users who have enabled it.

**Solutions and Mitigations:**

The issue is resolved in version 8.19.13, 9.2.5 .

**For Users that Cannot Upgrade:**

1. Disable the remote\_write module if it is not required for operations:
  - Remove or comment out the Prometheus `remote_write` configuration block in `metricbeat.yml`
  - Restart Metricbeat to apply changes

2. Restrict network access using firewall rules or network policies:
  - Limit access to the `remote_write` endpoint to trusted Prometheus server IP addresses only
  - Use host: "localhost" binding if the Prometheus server runs on the same host

**Indicators of Compromise (IOC)**

Log Patterns:

- Metricbeat process termination with “out of memory" messages in system logs
- Repeated Metricbeat crashes or restarts when the Prometheus `remote_write` module is enabled
- OOM events in kernel logs `dmesg` or container orchestration logs targeting the Metricbeat process

Audit Trail Indicators:

- Sudden memory consumption spikes in Metricbeat process metrics immediately preceding process termination
- Network connections from unexpected or unauthorized source IP addresses to the `remote_write` endpoint port

**Severity:** CVSSv3.1: Medium ( 5.7 ) - CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H  
**CVE ID** : CVE-2026-26931  
**Problem Type:** CWE-789 - Memory Allocation with Excessive Size Value  
**Impact:** CAPEC-130 - Excessive Allocation

---

_[View the full topic](https://discuss.elastic.co/t/metricbeat-8-19-13-9-2-5-security-update-esa-2026-09/385532)._
