6.8
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Description
Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.
Basic Information
ID
CVE-2025-37731
Source
elastic
Published
Dec 15, 2025 at 10:42
Affected Product
Vendor
Elastic
Product
Elasticsearch
Version
7.0.0
Affected Versions
Elastic Elasticsearch 7.0.0
Elastic Elasticsearch 8.0.0
Elastic Elasticsearch 9.0.0
Elastic Elasticsearch 9.2.0
Elastic Elasticsearch 8.0.0
Elastic Elasticsearch 9.0.0
Elastic Elasticsearch 9.2.0