CVE-2026-72649: Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code Execution
Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause attacker-controlled logic to execute with a materially broader system-call surface than intended. Exploitation requires an authenticated user with sufficient privileges to create and deploy trained models.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires an authenticated user with sufficient privileges to create and deploy trained models. Unauthenticated attackers are not described as able to exploit it.
Which Elasticsearch functionality is involved?
The issue is in the machine learning component and is triggered through a specially crafted trained model artifact. Environments that do not allow users to create and deploy trained models are not described as exposed through this path.