EIQ-2026-0003#

ID

EIQ-2026-0003

CVE

CVE-2026-56149

Description

Allocation of resources without limits or throttling in Elasticsearch

Date

14 July 2026

Severity

1 - LOW

CVSSv3 score

2.4

Status

Assessment

Allocation of resources without limits or throttling in Elasticsearch. Exploit requires a user with permissions to create or managed trained models. EclecticIQ Intelligence Center does not make use of Elasticsearch’s trained models feature. To trigger this exploit, the attacker needs to be authenticated as a user of the EclecticIQ Intelligence Center with modify kibana permissions or be assigned admin. Or the attacker must be able to access the Elasticsearch cluster directly as an Elasticsearch with permissions to create or managed trained models.

By default, all Elasticsearch access is either mediated through the EclecticIQ Intelligence Center, or a user must access the Elasticsearch cluster directly using one of the EclecticIQ Intelligence Center’s provisioned Elasticsearch users. Elasticsearch machine learning features are not exercised by any of EclecticIQ Intelligence Center functionality.

EIQ CVSS3.1: 2.4 AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:L

Links:

Mitigation

Upgrade to IC 3.8.0 when available, which ships with Elasticsearch 9.4.3.

Affected versions

EIQ Intelligence Center 3.7.2 and older, or any instance using Elasticsearch versions 8.x up to 8.19.16 (inclusive), 9.x up to 9.3.5 (inclusive), 9.4.x up to 9.4.2 (inclusive).

Notes

N/A