CVE-2026-0530

EUVD-2026-2039
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted request. This causes the application to perform redundant processing operations that continuously consume system resources until service degradation or complete unavailability occurs.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
elasticCNA
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 15%
Affected Products (NVD)
VendorProductVersion
elastickibana
7.10.0 ≤
𝑥
< 7.17.29
elastickibana
8.0.0 ≤
𝑥
< 8.19.10
elastickibana
9.0.0 ≤
𝑥
< 9.1.10
elastickibana
9.2.0 ≤
𝑥
< 9.2.4
𝑥
= Vulnerable software versions