EIQ-2026-0004#
ID |
EIQ-2026-0004 |
|---|---|
CVE |
CVE-2026-56145 |
Description |
Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
Date |
30 July 2026 |
Severity |
2 - MEDIUM |
CVSSv3 score |
6.5 |
Status |
⏲ |
Assessment |
Uncontrolled Resource Consumption in Elasticsearch. A low-privileged authenticated user with permission to execute EQL sequence queries against an index they control can send a specially crafted query that triggers excessive memory consumption, causing the Elasticsearch node to crash. To trigger this exploit, the attacker would need to be authenticated as a user of the EclecticIQ Intelligence Center, or have compromised access to Elasticsearch users, and execute EQL queries directly against Elasticsearch. By default, all Elasticsearch access is either mediated through the EclecticIQ Intelligence Center, or a user must access the Elasticsearch cluster directly using one of EclecticIQ Intelligence Center’s provisioned Elasticsearch users. EclecticIQ Intelligence Center does not use or expose EQL (Event Query Language) sequence queries. To exploit this, an attacker would need direct access to the Elasticsearch cluster API. Elastic CVSS3.1: 6.5 AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Links: |
Mitigation |
Upgrade to IC 3.8.0 when available, which ships with Elasticsearch 9.4.4. Administrators should restrict direct access to the Elasticsearch REST API to only trusted hosts and services. Do not expose Elasticsearch ports (9200/9300) to end users or untrusted networks. |
Affected versions |
EIQ Intelligence Center 3.7.2 and older, or any instance using Elasticsearch versions 8.x up to 8.19.17 (inclusive), 9.x up to 9.3.6 (inclusive), 9.4.x up to 9.4.3 (inclusive). |
Notes |
N/A |