Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-72649

Elasticsearch: remote code execution through deserialization of a crafted trained model

Technology

Elasticsearch

CVSS Score

8.8 / 10.0

Affected Versions

8.0.0 to 8.19.19; 9.0.0 to 9.4.4; 9.5.0

Upstream Fix

8.19.20; 9.4.5; 9.5.1

Published

September 1, 2026

OSSeva Coverage

Fixed upstream

Description

Deserialization of untrusted data in the Elasticsearch machine learning component lets a specially crafted trained model artifact run attacker-controlled logic with a broader system-call surface than intended. Exploitation needs an account authorized to create trained models, upload their definitions and start a model deployment; clusters with machine learning disabled or no machine learning capacity are not affected. Elastic's workaround is to set xpack.ml.enabled: false on all nodes and not to upload third-party trained models. CVSS is Elastic's score as the CNA.

Upstream record: NVD · CVE.org

Is your Elasticsearch deployment affected?

If you're running 8.0.0 to 8.19.19; 9.0.0 to 9.4.4; 9.5.0, you need this patch. Book a discovery call to get covered.