EIQ-2026-0011#
ID |
EIQ-2026-0011 |
|---|---|
CVE |
CVE-2026-63263 |
Description |
Uncontrolled Resource Consumption in Elasticsearch ES|QL Leading to Denial of Service |
Date |
30 July 2026 |
Severity |
1 - LOW |
CVSSv3 score |
2.2 |
Status |
⏲ |
Assessment |
Uncontrolled Resource Consumption in Elasticsearch’s ES|QL query engine. An authenticated user can submit a specially crafted ES|QL query that causes exponential CPU consumption during evaluation. Because the resource exhaustion persists beyond query completion, repeated requests can fully exhaust available query worker resources, rendering ES|QL queries unavailable until the node is restarted. Affected nodes can see high prolonged CPU consumption, and may cause other services on the node to degrade, but does not make them unavailable. EclecticIQ Intelligence Center does not use ES|QL (Event Query Language) features. To exploit this, an attacker needs direct access to the Elasticsearch cluster API. Elastic CVSS3.1: 6.5 AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H EIQ CVSS3.1: 2.2 AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L Links: |
Mitigation |
Upgrade to IC 3.8.0 when available, which ships with Elasticsearch 9.4.4. Administrators should restrict direct access to the Elasticsearch REST API to only trusted hosts and services. Do not expose Elasticsearch ports (9200/9300) to end users or untrusted networks. |
Affected versions |
EIQ Intelligence Center 3.7.2 and older, or any instance using Elasticsearch versions 8.x up to 8.19.18 (inclusive), 9.x up to 9.3.7 (inclusive), 9.4.x up to 9.4.3 (inclusive). |
Notes |
N/A |