CVE-2026-72642
Elasticsearch: out-of-range pointer offset in the machine learning native inference process
Technology
Elasticsearch
CVSS Score
8.8 / 10.0
Affected Versions
8.19.0 to 8.19.19; 9.4.0 to 9.4.4; 9.5.0
Upstream Fix
8.19.20; 9.4.5; 9.5.1
Published
August 13, 2026
OSSeva Coverage
Fixed upstream
Description
The native inference process that evaluates uploaded machine learning models accepts a model operation that computes a memory address from an offset inside the model without checking that it stays within the underlying storage. A user with the privileges to upload and deploy a trained model can craft one that reads and writes memory outside the allocation, crashing the inference process and, with enough control over the heap layout, possibly running code in that process. Affects deployments with machine learning enabled and at least one machine learning node. CVSS is Elastic's score as the CNA.
Is your Elasticsearch deployment affected?
If you're running 8.19.0 to 8.19.19; 9.4.0 to 9.4.4; 9.5.0, you need this patch. Book a discovery call to get covered.