{"id":"AZL-98451","summary":"CVE-2026-72649 affecting package rubygem-elasticsearch 8.9.0-1","details":"Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause attacker-controlled logic to execute with a materially broader system-call surface than intended. Exploitation requires an authenticated user with sufficient privileges to create and deploy trained models.","modified":"2026-09-03T05:27:10Z","published":"2026-09-01T20:17:16Z","upstream":["CVE-2026-72649"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72649"}],"affected":[{"package":{"name":"rubygem-elasticsearch","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/rubygem-elasticsearch"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"8.9.0-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-98451.json"}}],"schema_version":"1.9.0"}