CVE-2026-0530: Elastic Kibana

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted request. This causes the application to perform redundant processing operations that continuously consume system resources until service degradation or complete unavailability occurs.

Affected products

  • Elastic Kibana: from 7.10.0, before 7.17.29 (fixed in 7.17.29); from 8.0.0, before 8.19.10 (fixed in 8.19.10); from 9.0.0, before 9.1.10 (fixed in 9.1.10); from 9.2.0, before 9.2.4 (fixed in 9.2.4)

Published 2026-01-13. Last modified 2026-06-17.