EIQ-2026-0013#
ID |
EIQ-2026-0013 |
|---|---|
CVE |
Multiple (see assessment) |
Description |
Cumulative Elasticsearch vulnerabilities |
Date |
30 August 2026 |
Severity |
1 - LOW |
Status |
⏲ |
Assessment |
This advisory consolidates 14 Elasticsearch security advisories published by Elastic in August 2026, covering Elasticsearch versions up to and including 8.19.19. EclecticIQ Intelligence Center by default mitigates these vulnerabilities by restricting API access to Elasticsearch, or does not exercise the features affected by these vulnerabilities. The following Elasticsearch advisories are covered by this cumulative advisory.
|
Mitigation |
Upgrade to IC 3.8.1 or newer, when available. IC 3.8.1 ships with Elasticsearch 9.4.5. EclecticIQ Intelligence Center does not expose the Elasticsearch REST API directly to end users – all search queries that reach Elasticsearch are mediated by the EclecticIQ Intelligence Center. Administrators should restrict direct access to the Elasticsearch REST API to only trusted hosts and services. |
Affected versions |
EIQ Intelligence Center 3.7.2 and older, or any instance using Elasticsearch versions up to 8.19.19 (inclusive) or 9.x up to 9.4.4 (inclusive). |
Notes |
N/A |