Executive brief
Elastic Fleet Server, which centrally manages Elastic Agents, is vulnerable to a denial-of-service attack. An attacker can send a specifically designed request to a file upload endpoint that forces the server to consume excessive memory. This can cause the server to crash or become unresponsive, disrupting the management of security agents across the organization.
Technical details
A resource exhaustion vulnerability (CWE-770) exists in Elastic Fleet Server's upload endpoint. The component fails to properly throttle or limit memory allocation during certain request types, leading to Excessive Allocation (CAPEC-130). An attacker with low-level authenticated access can submit a specially crafted request that exhausts available system memory, resulting in a denial-of-service (DoS) condition. The vulnerability is reachable over the network and does not require user interaction. Patches are available in versions 8.19.11, 9.2.5, and 9.3.0.
Affected products
- Elastic Fleet Server 8.0.0 to 8.19.10, 9.0.0 to 9.2.4
Timeline
- 2026-07-01: disclosed
- 2026-07-01: advisory
- 2026-07-01: patched