EIQ-2026-0013#

ID

EIQ-2026-0013

CVE

Multiple (see assessment)

Description

Cumulative Elasticsearch vulnerabilities

Date

30 August 2026

Severity

1 - LOW

Status

Assessment

This advisory consolidates 14 Elasticsearch security advisories published by Elastic in August 2026, covering Elasticsearch versions up to and including 8.19.19.

EclecticIQ Intelligence Center by default mitigates these vulnerabilities by restricting API access to Elasticsearch, or does not exercise the features affected by these vulnerabilities. The following Elasticsearch advisories are covered by this cumulative advisory.

Mitigation

Upgrade to IC 3.8.1 or newer, when available. IC 3.8.1 ships with Elasticsearch 9.4.5.

EclecticIQ Intelligence Center does not expose the Elasticsearch REST API directly to end users – all search queries that reach Elasticsearch are mediated by the EclecticIQ Intelligence Center.

Administrators should restrict direct access to the Elasticsearch REST API to only trusted hosts and services.

Affected versions

EIQ Intelligence Center 3.7.2 and older, or any instance using Elasticsearch versions up to 8.19.19 (inclusive) or 9.x up to 9.4.4 (inclusive).

Notes

N/A