PT-2026-84388 · Elastic · Elasticsearch

CVE-2026-72649

·

Published

2026-09-01

·

Updated

2026-09-03

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Elasticsearch (affected versions not specified)
Description Deserialization of untrusted data in the machine learning component allows remote code execution through object injection. An attacker can use a specially crafted trained model artifact to execute controlled logic with a broader system-call surface than intended. This requires an authenticated user with sufficient privileges to create and deploy trained models.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-98451
BIT-ELASTICSEARCH-2026-72649
CVE-2026-72649

Affected Products

Elasticsearch