CVE-2026-26931: Elastic Metricbeat

Medium severity, CVSS 5.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).

Affected products

  • Elastic Metricbeat: from 8.0.0, before 8.19.13 (fixed in 8.19.13); from 9.0.0, before 9.2.5 (fixed in 9.2.5)

Published 2026-03-19. Last modified 2026-09-04.