EIQ-2026-0005#

ID

EIQ-2026-0005

CVE

CVE-2026-63136

Description

Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service

Date

30 July 2026

Severity

2 - MEDIUM

CVSSv3 score

6.5

Status

Assessment

Uncontrolled Resource Consumption in Elasticsearch. A user with search privileges can submit a specially crafted search request that causes a data node to exhaust available heap memory, resulting in node unavailability and cluster degradation. An attacker could leverage this to cause cluster downtime requiring manual intervention to restore service.

To trigger this exploit, the attacker would need to be authenticated as a user of the EclecticIQ Intelligence Center, or have compromised access to Elasticsearch users.

On EclecticIQ Intelligence Center, a user with read entities permissions can trigger this vulnerability by sending a specially crafted malicious payload to the IC’s private REST API.

Links:

Mitigation

Upgrade to IC 3.8.0 when available, which ships with Elasticsearch 9.4.4.

Affected versions

EIQ Intelligence Center 3.7.1 and older, or any instance using Elasticsearch versions 8.x up to 8.19.14 (inclusive), 9.x up to 9.2.8 (inclusive), 9.3.x up to 9.3.3 (inclusive).

Notes

N/A