CVE-2026-72649(elastic / elasticsearch)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause attacker-controlled logic to execute with a materially broader system-call surface than intended. Exploitation requires an authenticated user with sufficient privileges to create and deploy trained models.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • elasticsearch

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
elasticsearch

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-28: 109-28
Referenced assets1 URL
By indicator
Full discourse1 post
  • Prateek Tomar@Prateektomar

    Security advisory: CVE-2026-72649 with a CVSS score of 8.8. Deserialization of Untrusted Data CWE-502 in the.... Check if you need to take action. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    0000038
    134 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appelasticelasticsearch---
Appelasticelasticsearch9.5.0--

Explore more