CVE-2026-0530

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/01/2026
Last modified:
22/01/2026

Description

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted request. This causes the application to perform redundant processing operations that continuously consume system resources until service degradation or complete unavailability occurs.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* 7.10.0 (including) 7.17.29 (excluding)
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* 8.0.0 (including) 8.19.10 (excluding)
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* 9.0.0 (including) 9.1.10 (excluding)
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* 9.2.0 (including) 9.2.4 (excluding)