EIQ-2026-0007#
ID |
EIQ-2026-0007 |
|---|---|
CVE |
CVE-2026-63140 |
Description |
Reachable Assertion in Elasticsearch Leading to Denial of Service |
Date |
30 July 2026 |
Severity |
2 - MEDIUM |
CVSSv3 score |
6.5 |
Status |
⏲ |
Assessment |
Reachable Assertion in Elasticsearch. A specially crafted search request containing a null value in a specific query clause causes an internal assertion to be raised during query parsing. Because Elasticsearch treats assertion failures as fatal errors, this terminates the affected node process. A low-privileged authenticated user with read access to at least one index can exploit this condition with a single request to cause a node to terminate. To trigger this exploit, the attacker would need to be authenticated as a user of the EclecticIQ Intelligence Center, or have compromised access to Elasticsearch users. On EclecticIQ Intelligence Center, a user with Links: |
Mitigation |
Upgrade to IC 3.8.0 when available, which ships with Elasticsearch 9.4.4. |
Affected versions |
EIQ Intelligence Center 3.7.2 and older, or any instance using Elasticsearch versions 8.x up to 8.19.18 (inclusive), 9.x up to 9.3.7 (inclusive), 9.4.x up to 9.4.3 (inclusive). |
Notes |
N/A |