Vulnerability Intelligence Report
Use of Out-of-range Pointer Offset in the Elasticsearch Machine Learning Native Inference Process
CVE-2026-72642
The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset supplied inside the model, without validating that the offset stays within the bounds of the underlying storage. A user with the privileges required to upload and deploy a trained model can craft a model that reads and writes memory outside the intended allocation. The result is heap corruption that crashes the inference process, and, with sufficient control over the heap layout, could allow arbitrary code execution in the context of that process.
No Active Exploit Signals
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-823 ↗CWE-823 Use of Out-of-range Pointer Offset
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Elastic | Elasticsearch | 8.19.0 <= 8.19.19 (affected), 9.4.0 <= 9.4.4 (affected), 9.5.0 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Elastic · Vendor · Netherlands |
| Reserved | 2026-08-10T11:17:35 |
| Published | 2026-08-13T19:13:45 |
| Last Updated | 2026-08-14T03:56:07 |
Community Chatter & Buzz