CVE-2026-0531
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted bulk retrieval request. This requires an attacker to have low-level privileges equivalent to the viewer role, which grants read access to agent policies. The crafted request can cause the application to perform redundant database retrieval operations that immediately consume memory until the server crashes and becomes unavailable to all users.
- Elastic Kibana
- < 7.17.29, 8.19.10, 9.1.10, 9.2.4
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.4% (34th percentile)
- Weakness
- CWE-770
- NVD status
- Analyzed
- Published
- 2026-01-13
- Attack patterns
- CAPEC-130
CVE-2026-0531 at NVD
No indexed exploits for CVE-2026-0531 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-0531 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.