Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-72642

Elasticsearch: out-of-range pointer offset in the machine learning native inference process

Technology

Elasticsearch

CVSS Score

8.8 / 10.0

Affected Versions

8.19.0 to 8.19.19; 9.4.0 to 9.4.4; 9.5.0

Upstream Fix

8.19.20; 9.4.5; 9.5.1

Published

August 13, 2026

OSSeva Coverage

Fixed upstream

Description

The native inference process that evaluates uploaded machine learning models accepts a model operation that computes a memory address from an offset inside the model without checking that it stays within the underlying storage. A user with the privileges to upload and deploy a trained model can craft one that reads and writes memory outside the allocation, crashing the inference process and, with enough control over the heap layout, possibly running code in that process. Affects deployments with machine learning enabled and at least one machine learning node. CVSS is Elastic's score as the CNA.

Upstream record: NVD · CVE.org

Is your Elasticsearch deployment affected?

If you're running 8.19.0 to 8.19.19; 9.4.0 to 9.4.4; 9.5.0, you need this patch. Book a discovery call to get covered.