
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-72649 is a Deserialization of Untrusted Data vulnerability (CWE-502) in the Elasticsearch machine learning component that can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact can cause attacker-controlled logic to execute with a broader system-call surface than intended. Affected versions include Elasticsearch 8.0.0 through 8.19.19, 9.0.0 through 9.4.4, and 9.5.0. The vulnerability was published on September 1, 2026, with patches released on September 3, 2026. It carries a CVSS v3.1 base score of 8.8 (High) (Elastic Advisory, MSRC).
The root cause is improper deserialization of untrusted data (CWE-502) within Elasticsearch's machine learning component, specifically during the loading and deployment of trained model artifacts. An attacker can craft a malicious model artifact that, when deserialized by the Elasticsearch process, triggers object injection (CAPEC-586) and executes attacker-controlled logic with the privileges of the Elasticsearch service. Exploitation requires network access and an authenticated account with sufficient privileges to create and deploy trained models — meaning it is not exploitable by arbitrary low-privileged users, but by those with ML model management rights. No public proof-of-concept code has been identified at this time (Elastic Advisory, OSV).
Successful exploitation allows an authenticated attacker to execute arbitrary code remotely on the Elasticsearch host with the privileges of the Elasticsearch process, resulting in high confidentiality, integrity, and availability impact. This could enable full compromise of the Elasticsearch node, unauthorized access to indexed data (which may include sensitive or regulated information), and potential lateral movement within the cluster or connected infrastructure. The scope is limited to the affected Elasticsearch instance, but data exposure risk is significant given Elasticsearch's common role as a data store for logs, application data, and analytics (Elastic Advisory).
As of the time of publication, there is no evidence of active in-the-wild exploitation and no public proof-of-concept exploit has been identified (Elastic Advisory). The NVD SSVC assessment classifies exploitation as "none" and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.567%, reflecting a low current probability of exploitation in the wild. Exploitation is constrained by the requirement for an authenticated user with ML model deployment privileges, reducing the attack surface compared to unauthenticated vulnerabilities.
machine_learning_admin role or equivalent).PUT /_ml/trained_models/<model_id>) to upload the malicious artifact, then trigger deployment via the appropriate API call./_ml/trained_models/ endpoints from unfamiliar source IPs or accounts.elasticsearch.log) around model loading events.bash, sh, curl, wget, python) that are not part of normal Elasticsearch operation.Elastic has released patched versions: 8.19.20, 9.4.5, and 9.5.1. Upgrading to one of these versions is the primary recommended remediation (Elastic Advisory). As a workaround where immediate patching is not possible, restrict the ability to create and deploy trained models to explicitly trusted users only by tightening role-based access controls (e.g., limiting assignment of the machine_learning_admin role). Additionally, consider disabling Elasticsearch machine learning functionality entirely if it is not required for business operations, and monitor and audit all model deployment activities for anomalous behavior.
The vulnerability was covered in BleepingComputer's roundup of Microsoft's September 2026 Patch Tuesday, which noted 966 flaws addressed that cycle (BleepingComputer). A post on Bluesky from the CyberHub blog highlighted the vulnerability shortly after disclosure. Security tracking platforms including VulDB, OSV, and Tenable (Nessus plugin 344317) indexed the vulnerability promptly. No significant independent researcher commentary or controversy has been observed beyond standard aggregation and tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."