Resource Management Flaw in Kibana Fleet by Elastic
CVE-2026-0531
6.5MEDIUM
What is CVE-2026-0531?
A resource management flaw in Kibana Fleet allows attackers to exploit excessive resource allocation through specially crafted bulk retrieval requests. By leveraging low-level privileges akin to the viewer role, an attacker can trigger the application to execute redundant database operations, rapidly consuming memory resources. This can lead to application crashes and make the service unavailable for legitimate users, posing a significant risk to the integrity and availability of the affected systems.
Affected Version(s)
Kibana 7.10.0 <= 7.17.29
Kibana 8.0.0 <= 8.19.9
Kibana 9.0.0 <= 9.1.9