CVE-2025-37731
Elasticsearch PKI realm: user impersonation through crafted client certificates
Technology
Elasticsearch
CVSS Score
7.4 / 10.0
Affected Versions
All 7.x; 8.0.0 to 8.19.7; 9.0.0 to 9.1.7; 9.2.0 to 9.2.1
Upstream Fix
8.19.8; 9.1.8; 9.2.2
Published
December 15, 2025
OSSeva Coverage
Fixed upstream
Description
Improper authentication in the Elasticsearch PKI realm can let an attacker impersonate a user with a specially crafted client certificate. The certificate must be signed by a legitimate Certificate Authority that the cluster trusts. Only deployments that use the PKI realm are affected. NVD scores the record 7.4; Elastic scores it 6.8.
Is your Elasticsearch deployment affected?
If you're running All 7.x; 8.0.0 to 8.19.7; 9.0.0 to 9.1.7; 9.2.0 to 9.2.1, you need this patch. Book a discovery call to get covered.