216.73.217.22

CVE-2026-0531

· Published 13/01/2026 21:15 · Modified 14/01/2026 16:25

Labels: CVE-2026-0531 2026-01-13CVE-2026-0531CWE-770[email protected]

Essential information

Published
13/01/2026 21:15
Modified
14/01/2026 16:25
Author
Creator
CVSS
6.5 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVSS metrics

Description

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted bulk retrieval request. This requires an attacker to have low-level privileges equivalent to the viewer role, which grants read access to agent policies. The crafted request can cause the application to perform redundant database retrieval operations that immediately consume memory until the server crashes and becomes unavailable to all users.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
elastic / kibana cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

References