EIQ-2026-0007#

ID

EIQ-2026-0007

CVE

CVE-2026-63140

Description

Reachable Assertion in Elasticsearch Leading to Denial of Service

Date

30 July 2026

Severity

2 - MEDIUM

CVSSv3 score

6.5

Status

Assessment

Reachable Assertion in Elasticsearch. A specially crafted search request containing a null value in a specific query clause causes an internal assertion to be raised during query parsing. Because Elasticsearch treats assertion failures as fatal errors, this terminates the affected node process. A low-privileged authenticated user with read access to at least one index can exploit this condition with a single request to cause a node to terminate.

To trigger this exploit, the attacker would need to be authenticated as a user of the EclecticIQ Intelligence Center, or have compromised access to Elasticsearch users.

On EclecticIQ Intelligence Center, a user with read entities permissions can trigger this vulnerability by sending a specially crafted malicious payload to the IC’s private REST API.

Links:

Mitigation

Upgrade to IC 3.8.0 when available, which ships with Elasticsearch 9.4.4.

Affected versions

EIQ Intelligence Center 3.7.2 and older, or any instance using Elasticsearch versions 8.x up to 8.19.18 (inclusive), 9.x up to 9.3.7 (inclusive), 9.4.x up to 9.4.3 (inclusive).

Notes

N/A