Deserialization of Untrusted Data in Elasticsearch - CVE-2026-72649
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to deserialization of untrusted data in the Elasticsearch machine learning component when processing a specially crafted trained model artifact. A remote user can upload and deploy a crafted trained model artifact to execute arbitrary code.
Only deployments with machine learning capacity enabled are affected.