# Packetbeat 8.19.10, 9.1.10, 9.2.4 Security Update (ESA-2026-02)

**URL:** <https://discuss.elastic.co/t/packetbeat-8-19-10-9-1-10-9-2-4-security-update-esa-2026-02/384520>\
**Category:** Security Announcements\
**Created:** [January 13, 2026, 8:43pm UTC](https://discuss.elastic.co/t/packetbeat-8-19-10-9-1-10-9-2-4-security-update-esa-2026-02/384520 "2026-01-13T20:43:19Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [January 13, 2026, 8:43pm UTC](https://discuss.elastic.co/t/packetbeat-8-19-10-9-1-10-9-2-4-security-update-esa-2026-02/384520/1 "2026-01-13T20:43:19Z")

</div>

### Improper Validation of Array Index in Packetbeat Leading to Overflow Buffers (ESA-2026-02)

Improper Validation of Array Index (CWE-129) in Packetbeat’s MongoDB protocol parser can allow an attacker to cause Overflow Buffers (CAPEC-100) through specially crafted network traffic. This requires an attacker to send a malformed payload to a monitored network interface where MongoDB protocol parsing is enabled.

### Affected Versions:

- 7.x: All versions
- 8.x: All versions from 8.0.0 up to and including 8.19.9
- 9.x:
  - All versions from 9.0.0 up to and including 9.1.9
  - All versions from 9.2.0 up to and including 9.2.3

### Solutions and Mitigations:

The issue is resolved in version 8.19.10, 9.1.10, 9.2.4.

### For Users that Cannot Upgrade:

There are no workarounds

### Acknowledgements:

We would like to thank AISLE Research for responsibly disclosing this vulnerability to Elastic

**Severity** : CVSSv3.1: Medium (6.5) - AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

**CVE ID** : CVE-2026-0529

**Problem Type** : CWE-129 - Improper Validation of Array Index

**Impact:** CAPEC-100 - Overflow Buffers

---

_[View the full topic](https://discuss.elastic.co/t/packetbeat-8-19-10-9-1-10-9-2-4-security-update-esa-2026-02/384520)._
