Record summary

CVE-2025-37731 has a selected CVSS score of 6.8 (medium).

Description

Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 16, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List7.0.0 to ≤ 7.17.29affected
8.0.0 to ≤ 8.19.7affected
9.0.0 to ≤ 9.1.7affected
9.2.0 to ≤ 9.2.1affected

org.elasticsearch:elasticsearch

Browse Maven / org.elasticsearch:elasticsearch
GitHub Advisory7.0.0-alpha1 to < 8.19.8 · Fixed in 8.19.8affected
9.0.0-beta1 to < 9.1.8 · Fixed in 9.1.8affected
9.2.0 to < 9.2.2 · Fixed in 9.2.2affected

References

6