EIQ-2026-0002#

ID

EIQ-2026-0002

CVE

CVE-2026-56148

Description

Uncontrolled recursion in Elasticsearch

Date

14 July 2026

Severity

1 - LOW

CVSSv3 score

3.5

Status

Assessment

Uncontrolled recursion in Elasticsearch. Exploit is triggered with a specially crafted query, sent by an authorized user, that can consume excessive resources on affected node, making it unavailable.

To trigger this exploit, the attacker would need to be authenticated as a user of the EclecticIQ Intelligence Center, or have compromised access to Elasticsearch users. By default, all Elasticsearch access is either mediated through the EclecticIQ Intelligence Center, or a user must access the Elasticsearch cluster directly using one of the EclecticIQ Intelligence Center’s provisioned Elasticsearch users.

EIQ CVSS3.1: 3.5 AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L

Links:

Mitigation

Upgrade to IC 3.8.0 when available, which ships with Elasticsearch 9.4.3.

Affected versions

EIQ Intelligence Center 3.7.2 and older, or any instance using Elasticsearch versions 8.x up to 8.19.16 (inclusive), 9.x up to 9.3.5 (inclusive), 9.4.x up to 9.4.2 (inclusive).

Notes

N/A