Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-56150— Allocation of Resources Without Limits or Throttling in Fleet Server Leading to Denial of Service

CVSS 6.5 · Medium EPSS 0.35% · P27

Affected Version Matrix 2

VendorProductVersion RangeStatus
ElasticFleet Server9.0.0≤ 9.2.4affected
8.0.0≤ 8.19.10affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-56150

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Allocation of Resources Without Limits or Throttling in Fleet Server Leading to Denial of Service
Source: CVE Program / CVE List V5
Vulnerability Description
Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker can submit a specially crafted request to an upload endpoint that causes excessive memory consumption, which may render Fleet Server unavailable.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5
Vulnerability Title
Elastic Fleet Server 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Elastic Fleet Server是荷兰Elastic公司开源的一个设备集中管理服务。 Elastic Fleet Server 9.0.0至9.2.4版本和8.0.0至8.19.10版本存在资源管理错误漏洞,该漏洞源于资源无限制分配或节流问题,可能导致攻击者向上传端点提交特制请求,造成大量内存消耗,从而使得Fleet Server无法使用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
ElasticFleet Server 9.0.0 ~ 9.2.4 -

II. Public POCs for CVE-2026-56150

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-56150

登录查看更多情报信息。

Vendor Advisories for CVE-2026-56150 (1)

Same Patch Batch · Elastic · 2026-07-01 · 9 CVEs total

CVE-2026-490918.0 HIGHImproper Output Neutralization for Logs in Kibana Leading to Log Injection
CVE-2026-490906.5 MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
CVE-2026-490876.5 MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic
CVE-2026-561486.5 MEDIUMUncontrolled Recursion in Elasticsearch Leading to Denial of Service
CVE-2026-561516.5 MEDIUMImproper Input Validation in Kibana Leading to Denial of Service
CVE-2026-561525.3 MEDIUMIncorrect Authorization in Elastic Defend Leading to Information Disclosure
CVE-2026-561494.9 MEDIUMAllocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of
CVE-2026-490884.4 MEDIUMInsertion of Sensitive Information into Log File in Kibana Leading to Information Disclosu

IV. Related Vulnerabilities

V. Comments for CVE-2026-56150

No comments yet


Leave a comment