EIQ-2026-0002#
ID |
EIQ-2026-0002 |
|---|---|
CVE |
CVE-2026-56148 |
Description |
Uncontrolled recursion in Elasticsearch |
Date |
14 July 2026 |
Severity |
1 - LOW |
CVSSv3 score |
3.5 |
Status |
⏲ |
Assessment |
Uncontrolled recursion in Elasticsearch. Exploit is triggered with a specially crafted query, sent by an authorized user, that can consume excessive resources on affected node, making it unavailable. To trigger this exploit, the attacker would need to be authenticated as a user of the EclecticIQ Intelligence Center, or have compromised access to Elasticsearch users. By default, all Elasticsearch access is either mediated through the EclecticIQ Intelligence Center, or a user must access the Elasticsearch cluster directly using one of the EclecticIQ Intelligence Center’s provisioned Elasticsearch users. EIQ CVSS3.1: 3.5 AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L Links: |
Mitigation |
Upgrade to IC 3.8.0 when available, which ships with Elasticsearch 9.4.3. |
Affected versions |
EIQ Intelligence Center 3.7.2 and older, or any instance using Elasticsearch versions 8.x up to 8.19.16 (inclusive), 9.x up to 9.3.5 (inclusive), 9.4.x up to 9.4.2 (inclusive). |
Notes |
N/A |