8.8
CVE-2026-72649
- EPSS 0.58%
- Veröffentlicht 01.09.2026 19:20:17
- Zuletzt bearbeitet 02.09.2026 18:49:54
- Erkennungen
Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code Execution
Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause attacker-controlled logic to execute with a materially broader system-call surface than intended. Exploitation requires an authenticated user with sufficient privileges to create and deploy trained models.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Elastic ≫ Elasticsearch Version >= 8.0.0 < 8.19.20
Elastic ≫ Elasticsearch Version >= 9.0.0 < 9.4.5
Elastic ≫ Elasticsearch Version 9.5.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.58% | 0.455 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@elastic.co | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://discuss.elastic.co/t/elasticsearch-8-19-20-9-4-5-9-5-1-security-update-esa-2026-114/390087