Description
Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker can submit a specially crafted request to an upload endpoint that causes excessive memory consumption, which may render Fleet Server unavailable.
Published: 2026-07-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Elastic Fleet Server is vulnerable to an allocation of resources without limits or throttling flaw (CWE‑770). An attacker can send a specially crafted request to the server’s upload endpoint that causes the process to consume excessive memory, leading to memory exhaustion. The resulting denial of service can render the Fleet Server unavailable for legitimate users.

Affected Systems

The vulnerability affects Elastic’s Fleet Server product. The published data lists the vendor as Elastic and the product as Fleet Server, but no specific affected versions are documented, so users should assume all currently deployed instances could be vulnerable if they have not applied the latest patch.

Risk and Exploitability

The CVSS score of 6.5 classifies this vulnerability as moderate severity. The EPSS score of <1% indicates that exploitation is unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog, indicating limited known exploitation activity. Based on the description, the likely attack vector is a remotely sent crafted request to the upload endpoint without requiring elevated privileges. Successful exploitation would consume unresponsive, resulting in service disruption.

Generated by OpenCVE AI on July 21, 2026 at 13:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Elastic Fleet Server release that includes the fix for this resourceallocation flaw, as announced under ESA‑2026‑44.
  • Configure the upload endpoint to reject requests that are too large or sent too frequently, enforcing size and rate limits to prevent memory exhaustion.
  • Enforce operating‑system resource limits for the Fleet Server process, such as cgroup memory quotas, to cap its maximum memory consumption.
  • Implement monitoring of memory usage and alert on sudden increases, combined with network‑level rate limiting or a web application firewall to reduce abusive traffic.

Generated by OpenCVE AI on July 21, 2026 at 13:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic fleet Server
Vendors & Products Elastic
Elastic fleet Server

Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker can submit a specially crafted request to an upload endpoint that causes excessive memory consumption, which may render Fleet Server unavailable.
Title Allocation of Resources Without Limits or Throttling in Fleet Server Leading to Denial of Service
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Elastic Fleet Server
cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-07-01T17:25:09.438Z

Reserved: 2026-06-19T11:01:02.535Z

Link: CVE-2026-56150

cve-icon Vulnrichment

Updated: 2026-07-01T17:21:11.044Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T14:00:05Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling