Back to Vulnerability Directory
HIGHFixed upstream

CVE-2025-37731

Elasticsearch PKI realm: user impersonation through crafted client certificates

Technology

Elasticsearch

CVSS Score

7.4 / 10.0

Affected Versions

All 7.x; 8.0.0 to 8.19.7; 9.0.0 to 9.1.7; 9.2.0 to 9.2.1

Upstream Fix

8.19.8; 9.1.8; 9.2.2

Published

December 15, 2025

OSSeva Coverage

Fixed upstream

Description

Improper authentication in the Elasticsearch PKI realm can let an attacker impersonate a user with a specially crafted client certificate. The certificate must be signed by a legitimate Certificate Authority that the cluster trusts. Only deployments that use the PKI realm are affected. NVD scores the record 7.4; Elastic scores it 6.8.

Upstream record: NVD · CVE.org

Is your Elasticsearch deployment affected?

If you're running All 7.x; 8.0.0 to 8.19.7; 9.0.0 to 9.1.7; 9.2.0 to 9.2.1, you need this patch. Book a discovery call to get covered.