CVE-2026-0531 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted bulk retriev…
Medium CVSS: 6.5

CVE-2026-0531

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted bulk retrieval request. This requires an attacker to have low-level privileges equivalent to the viewer role, which grants read access to agent policies. The crafted request can cause the application to perform redundant database retrieval operations that immediately consume memory until the server crashes and becomes unavailable to all users.
Vendor
Elastic
Product
Kibana
CWE
CWE-770
Yayın Tarihi
2026-01-13 21:15:50
Güncelleme
2026-01-22 19:59:54
Source Identifier
security@elastic.co
KEV Date Added
-

Kategoriler

Referanslar