CVE-2026-72649
Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause attacker-controlled logic to execute with a materially broader system-call surface than intended. Exploitation requires an authenticated user with sufficient privileges to create and deploy trained models.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.58%
- CWE
- CWE-502
- Published
- 2026-09-01
- Last modified
- 2026-09-02
Affected products
- Elastic Elasticsearch
- Elastic Elasticsearch
- Elastic Elasticsearch
Weakness type
Related vulnerabilities
- CVE-2026-87719 — Deserialization of Untrusted Data in GitLab
- CVE-2026-82222 — WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
- CVE-2026-70416 — Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthentica
- CVE-2026-17061 — Deserialization of Untrusted Data Vulnerability in SIMULIA Execution Engine from Release 2023 through Release 2026
- CVE-2026-4703 — WS Form LITE <= 1.10.80 - Unauthenticated PHP Object Injection via Form Submission
- CVE-2026-20307 — Cisco Identity Services Engine Remote Code Execution Vulnerability
- CVE-2026-12650 — A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated
- CVE-2026-78006 — The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution