Echo: github.com/elastic/beats: security update to 7.0.0-alpha2.0.20260126223743-dec1b31111ec

medium Tenable Self-Hosted Container Security Plugin ID 460111

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead
Denial of Service via Input Data Manipulation (CAPEC-153). An attacker with the ability to send specially
crafted, malformed network packets to a monitored network interface can trigger out-of-bounds read
operations, resulting in application crashes or resource exhaustion. This requires the attacker to be
positioned on the same network segment as the Packetbeat deployment or to control traffic routed to
monitored interfaces. (CVE-2026-26933)

Solution

Update the github.com/elastic/beats library and its related packages to version 7.0.0-alpha2.0.20260126223743-dec1b31111ec or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-26933

Plugin Details

Severity: Medium

ID: 460111

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.73

CVSS v2

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.1

Vector: CVSS2#AV:A/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-26933

CVSS v3

Risk Factor: Medium

Base Score: 5.7

Temporal Score: 5

Vector: CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/28/2026

Vulnerability Publication Date: 3/19/2026

Reference Information

CVE: CVE-2026-26933