CVE-2026-72649 HIGH

CVE-2026-72649: Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code Execution

Vendor Elastic
Product Elasticsearch
Weakness CWE-502 · Unsafe deserialization
Published September 1, 2026
Last update September 2, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause attacker-controlled logic to execute with a materially broader system-call surface than intended. Exploitation requires an authenticated user with sufficient privileges to create and deploy trained models.

Key dates

02Disclosure timeline

September 1, 2026 CVE published
September 2, 2026 Record updated

Related vulnerabilities

04Related CVE