EIQ-2026-0004#

ID

EIQ-2026-0004

CVE

CVE-2026-56145

Description

Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service

Date

30 July 2026

Severity

2 - MEDIUM

CVSSv3 score

6.5

Status

Assessment

Uncontrolled Resource Consumption in Elasticsearch. A low-privileged authenticated user with permission to execute EQL sequence queries against an index they control can send a specially crafted query that triggers excessive memory consumption, causing the Elasticsearch node to crash.

To trigger this exploit, the attacker would need to be authenticated as a user of the EclecticIQ Intelligence Center, or have compromised access to Elasticsearch users, and execute EQL queries directly against Elasticsearch. By default, all Elasticsearch access is either mediated through the EclecticIQ Intelligence Center, or a user must access the Elasticsearch cluster directly using one of EclecticIQ Intelligence Center’s provisioned Elasticsearch users.

EclecticIQ Intelligence Center does not use or expose EQL (Event Query Language) sequence queries. To exploit this, an attacker would need direct access to the Elasticsearch cluster API.

Elastic CVSS3.1: 6.5 AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Links:

Mitigation

Upgrade to IC 3.8.0 when available, which ships with Elasticsearch 9.4.4.

Administrators should restrict direct access to the Elasticsearch REST API to only trusted hosts and services. Do not expose Elasticsearch ports (9200/9300) to end users or untrusted networks.

Affected versions

EIQ Intelligence Center 3.7.2 and older, or any instance using Elasticsearch versions 8.x up to 8.19.17 (inclusive), 9.x up to 9.3.6 (inclusive), 9.4.x up to 9.4.3 (inclusive).

Notes

N/A