CVE-2026-72649: Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code exec
Summary
Elasticsearch's machine learning component has a vulnerability where it unsafely processes untrusted data during deserialization (the conversion of saved data back into usable objects), allowing attackers to inject and execute malicious code through specially crafted trained models. An attacker would need valid authentication and permissions to create and deploy models to exploit this flaw.
Vulnerability Details
8.8(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
network
low
low
none
September 1, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-72649
First tracked: September 1, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 90%