discuss.elastic.co
https://discuss.elastic.co/t/elasticsearch-8-19-8-9-1-8-and-9-2-2-security-update-esa-2025-27/384063 CVE-2025-37731
MEDIUM
Elasticsearch Improper Authentication
Record summary
CVE-2025-37731 has a selected CVSS score of 6.8 (medium).
Description
Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 16, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
ElasticsearchBrowse Elastic / ElasticsearchDefault status: unaffected | CVE List | 7.0.0 to ≤ 7.17.29 | affected |
| 8.0.0 to ≤ 8.19.7 | affected | ||
| 9.0.0 to ≤ 9.1.7 | affected | ||
| 9.2.0 to ≤ 9.2.1 | affected | ||
org.elasticsearch:elasticsearchBrowse Maven / org.elasticsearch:elasticsearch | GitHub Advisory | 7.0.0-alpha1 to < 8.19.8 · Fixed in 8.19.8 | affected |
| 9.0.0-beta1 to < 9.1.8 · Fixed in 9.1.8 | affected | ||
| 9.2.0 to < 9.2.2 · Fixed in 9.2.2 | affected |
References
6github.com
https://github.com/elastic/elasticsearch github.com
https://github.com/elastic/elasticsearch/commit/cd97b8566bf56e628070021300784cb9cee0286f github.com
https://github.com/elastic/elasticsearch/commit/d8a408da79f214395845d99d241e832077045983 github.com
https://github.com/elastic/elasticsearch/commit/e519fe4c51a3c887675eb7daea2f914738847f23 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-37731