CVE-2026-72649
Elasticsearch: remote code execution through deserialization of a crafted trained model
Technology
Elasticsearch
CVSS Score
8.8 / 10.0
Affected Versions
8.0.0 to 8.19.19; 9.0.0 to 9.4.4; 9.5.0
Upstream Fix
8.19.20; 9.4.5; 9.5.1
Published
September 1, 2026
OSSeva Coverage
Fixed upstream
Description
Deserialization of untrusted data in the Elasticsearch machine learning component lets a specially crafted trained model artifact run attacker-controlled logic with a broader system-call surface than intended. Exploitation needs an account authorized to create trained models, upload their definitions and start a model deployment; clusters with machine learning disabled or no machine learning capacity are not affected. Elastic's workaround is to set xpack.ml.enabled: false on all nodes and not to upload third-party trained models. CVSS is Elastic's score as the CNA.
Is your Elasticsearch deployment affected?
If you're running 8.0.0 to 8.19.19; 9.0.0 to 9.4.4; 9.5.0, you need this patch. Book a discovery call to get covered.