CVE-2026-72642: The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset supplied inside the model, ...
Added to the CISA Known Exploited Vulnerabilities catalog on 13 Aug 2026. Vendor: AI/ML. Product: machine learning. CVSS score: 8.8.
The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset supplied inside the model, without validating that the offset stays within the bounds of the underlying storage. A user with th...
Required action: Review and patch if applicable to your AI infrastructure.