Impact
Deserialization of untrusted data in the Elasticsearch machine learning component can trigger remote code execution through object injection. A maliciously crafted trained model artifact allows the attacker to introduce attacker-controlled logic, leading to execution of arbitrary code with a broader system‑call surface than intended. This flaw provides full control over the Elasticsearch host for users who are able to deploy trained models.
Affected Systems
Elastic’s Elasticsearch product is affected. Specific product versions are not disclosed in the advisory, but all installations that include the machine learning component require assessment for the presence of this flaw.
Risk and Exploitability
The vulnerability scores a CVSS of 8.8, indicating high severity, and it is not listed in the CISA KEV catalog. An attacker must first be authenticated and possess sufficient privileges to create and deploy trained models. Once those prerequisites are met, the attacker can upload a malicious model, resulting in arbitrary code execution on the Elasticsearch cluster. The EPSS score is not available, so the exploitation probability is unknown, but the high CVSS suggests a significant potential impact if the required privileges exist.
OpenCVE Enrichment