Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 13 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted bulk retrieval request. This requires an attacker to have low-level privileges equivalent to the viewer role, which grants read access to agent policies. The crafted request can cause the application to perform redundant database retrieval operations that immediately consume memory until the server crashes and becomes unavailable to all users. | |
| Title | Allocation of Resources Without Limits or Throttling in Kibana Fleet | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-01-13T21:25:44.808Z
Reserved: 2025-12-19T15:59:24.984Z
Link: CVE-2026-0531
Updated: 2026-01-13T21:25:40.325Z
Status : Received
Published: 2026-01-13T21:15:50.990
Modified: 2026-01-13T21:15:50.990
Link: CVE-2026-0531
No data.
OpenCVE Enrichment
No data.