EIQ-2026-0011#

ID

EIQ-2026-0011

CVE

CVE-2026-63263

Description

Uncontrolled Resource Consumption in Elasticsearch ES|QL Leading to Denial of Service

Date

30 July 2026

Severity

1 - LOW

CVSSv3 score

2.2

Status

Assessment

Uncontrolled Resource Consumption in Elasticsearch’s ES|QL query engine. An authenticated user can submit a specially crafted ES|QL query that causes exponential CPU consumption during evaluation. Because the resource exhaustion persists beyond query completion, repeated requests can fully exhaust available query worker resources, rendering ES|QL queries unavailable until the node is restarted.

Affected nodes can see high prolonged CPU consumption, and may cause other services on the node to degrade, but does not make them unavailable.

EclecticIQ Intelligence Center does not use ES|QL (Event Query Language) features.

To exploit this, an attacker needs direct access to the Elasticsearch cluster API.

Elastic CVSS3.1: 6.5 AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EIQ CVSS3.1: 2.2 AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L

Links:

Mitigation

Upgrade to IC 3.8.0 when available, which ships with Elasticsearch 9.4.4.

Administrators should restrict direct access to the Elasticsearch REST API to only trusted hosts and services. Do not expose Elasticsearch ports (9200/9300) to end users or untrusted networks.

Affected versions

EIQ Intelligence Center 3.7.2 and older, or any instance using Elasticsearch versions 8.x up to 8.19.18 (inclusive), 9.x up to 9.3.7 (inclusive), 9.4.x up to 9.4.3 (inclusive).

Notes

N/A