Home

Description

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted bulk retrieval request. This requires an attacker to have low-level privileges equivalent to the viewer role, which grants read access to agent policies. The crafted request can cause the application to perform redundant database retrieval operations that immediately consume memory until the server crashes and becomes unavailable to all users.

PUBLISHED Reserved 2025-12-19 | Published 2026-01-13 | Updated 2026-01-13 | Assigner elastic




MEDIUM: 6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-770 Allocation of Resources Without Limits or Throttling

Product status

Default status
unaffected

7.10.0 (semver)
affected

8.0.0 (semver)
affected

9.0.0 (semver)
affected

9.2.0 (semver)
affected

Credits

vultza reporter

References

discuss.elastic.co/...2-4-security-update-esa-2026-04/384522

cve.org (CVE-2026-0531)

nvd.nist.gov (CVE-2026-0531)

Download JSON