Elastic
Elasticsearch
See the latest tracked release, confirm when it was published, and subscribe for update emails.
8.19.21
- Release date
- September 01, 2026
- Security status
- 2 high-severity CVEs tracked in the last 90 days. Current version not affected.
Source
GitHub API
Public release notes are linked for the latest stored release.
Release history
See the latest published releases stored for this product.
| Version | Published | Notes |
|---|---|---|
| 8.19.21 | 2026-09-01 | Release Notes |
| 8.19.20 | 2026-08-11 | Release Notes |
| 8.19.19 | 2026-07-21 | Release Notes |
| 8.19.18 | 2026-06-30 | Release Notes |
| 8.19.17 | 2026-06-23 | Release Notes |
| 8.19.16 | 2026-05-28 | Release Notes |
| 8.19.15 | 2026-04-30 | Release Notes |
| 8.19.14 | 2026-04-08 | Release Notes |
| 8.19.13 | 2026-03-19 | Release Notes |
Vulnerability tracking
versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.
Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.
| CVE | Severity | Published | Status | Summary |
|---|---|---|---|---|
| CVE-2026-72649 | HIGH (8.8) | 2026-09-01 | Current versionnot affected | Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause attacker-controlled logic to execute with a materially broader system-call surface than intended. Exploitation requires an authenticated user with sufficient privileges to create and deploy trained models. Affected versions
|
| CVE-2026-72642 | HIGH (8.8) | 2026-08-13 | Current versionnot affected | The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset supplied inside the model, without validating that the offset stays within the bounds of the underlying storage. A user with the privileges required to upload and deploy a trained model can craft a model that reads and writes memory outside the intended allocation. The result is heap corruption that crashes the inference process, and, with sufficient control over the heap layout, could allow arbitrary code execution in the context of that process. Affected versions
|