CVE-2026-0531

Source
https://cve.org/CVERecord?id=CVE-2026-0531
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-0531.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-0531
Aliases
Downstream
Related
Published
2026-01-13T21:15:50.990Z
Modified
2026-03-13T04:12:21.077593Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted bulk retrieval request. This requires an attacker to have low-level privileges equivalent to the viewer role, which grants read access to agent policies. The crafted request can cause the application to perform redundant database retrieval operations that immediately consume memory until the server crashes and becomes unavailable to all users.

References

Affected packages

Git / github.com/elastic/kibana

Affected ranges

Type
GIT
Repo
https://github.com/elastic/kibana
Events
Database specific
{
    "versions": [
        {
            "introduced": "7.10.0"
        },
        {
            "fixed": "7.17.29"
        },
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.19.10"
        },
        {
            "introduced": "9.0.0"
        },
        {
            "fixed": "9.1.10"
        },
        {
            "introduced": "9.2.0"
        },
        {
            "fixed": "9.2.4"
        }
    ]
}

Affected versions

v9.*
v9.2.0
v9.2.1
v9.2.2
v9.2.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-0531.json"