Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-72642— Use of Out-of-range Pointer Offset in the Elasticsearch Machine Learning Native Inference Process

CVSS 8.8 · High

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 3

VendorProductVersion RangeStatus
ElasticElasticsearch8.19.0≤ 8.19.19affected
9.4.0≤ 9.4.4affected
9.5.0affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-72642

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Use of Out-of-range Pointer Offset in the Elasticsearch Machine Learning Native Inference Process
Source: CVE Program / CVE List V5
Vulnerability Description
The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset supplied inside the model, without validating that the offset stays within the bounds of the underlying storage. A user with the privileges required to upload and deploy a trained model can craft a model that reads and writes memory outside the intended allocation. The result is heap corruption that crashes the inference process, and, with sufficient control over the heap layout, could allow arbitrary code execution in the context of that process.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
使用越界的指针偏移
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
ElasticElasticsearch 8.19.0 ~ 8.19.19 -

II. Public POCs for CVE-2026-72642

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-72642

登录查看更多情报信息。

Other References for CVE-2026-72642 (1)

Same Patch Batch · Elastic · 2026-08-13 · 48 CVEs total

CVE-2026-726658.1 HIGHMissing Authorization in Kibana Leading to Unauthorized Execution of Host Response Actions
CVE-2026-726707.7 HIGHExposure of Sensitive Information to an Unauthorized Actor in Kibana Leading to Disclosure
CVE-2026-726727.7 HIGHIncorrect Authorization in Kibana Leading to Disclosure of Elastic Defend Endpoint Event D
CVE-2026-726697.6 HIGHMissing Authorization in Kibana Leading to Cross-User Information Disclosure and Data Tamp
CVE-2026-726777.3 HIGHRelative Path Traversal in Kibana Fleet Leading to Unauthorized Deletion of Users and Othe
CVE-2026-726587.3 HIGHCross-Site Request Forgery in Kibana Leading to Privilege Escalation
CVE-2026-726297.1 HIGHAuthorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Space Access t
CVE-2026-726307.1 HIGHIncorrect Authorization in Kibana Fleet Leading to Privilege Escalation
CVE-2026-726757.1 HIGHMissing Authorization in Kibana Machine Learning Leading to Cross-Space Information Disclo
CVE-2026-726327.1 HIGHObservable Discrepancy in Kibana Fleet Leading to Disclosure of Elastic Agent Elasticsearc
CVE-2026-726437.1 HIGHIncorrect Authorization in Kibana Agent Builder Leading to Disclosure and Tampering of Pri
CVE-2026-726666.8 MEDIUMAuthorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Query E
CVE-2026-726746.5 MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic
CVE-2026-726606.5 MEDIUMUncaught Exception in Kibana Leading to Denial of Service
CVE-2026-726866.5 MEDIUMUncontrolled Recursion in Elasticsearch Leading to Denial of Service
CVE-2026-726846.5 MEDIUMAllocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of
CVE-2026-490896.5 MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic
CVE-2026-726516.5 MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic
CVE-2026-726616.5 MEDIUMMissing Authorization in Kibana Leading to Information Disclosure
CVE-2026-726316.5 MEDIUMImproper Privilege Management in Kibana Fleet Leading to Over-Scoped Elastic Agent API Key

Showing top 20 of 48 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-72642

No comments yet


Leave a comment