CVE-2026-56150

Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker can submit a specially crafted request to an upload endpoint that causes excessive memory consumption, which may render Fleet Server unavailable.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:elastic:fleet_server:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:fleet_server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-01 17:16

Updated : 2026-07-06 18:51


NVD link : CVE-2026-56150

Mitre link : CVE-2026-56150

CVE.ORG link : CVE-2026-56150


JSON object : View

Products Affected

elastic

  • fleet_server
CWE
CWE-770

Allocation of Resources Without Limits or Throttling