Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-98451.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-98451
Upstream
  • CVE-2026-72649
Published
2026-09-01T20:17:16Z
Modified
2026-09-03T05:27:10Z
Summary
CVE-2026-72649 affecting package rubygem-elasticsearch 8.9.0-1
Details

Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause attacker-controlled logic to execute with a materially broader system-call surface than intended. Exploitation requires an authenticated user with sufficient privileges to create and deploy trained models.

References

Affected packages

Azure Linux:3 / rubygem-elasticsearch

Package

Name
rubygem-elasticsearch
Purl
pkg:rpm/azure-linux/rubygem-elasticsearch

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
8.9.0-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-98451.json"