CVE Vulnerabilities

CVE-2025-37731

Improper Authentication

Published: Dec 15, 2025 | Modified: Dec 18, 2025
CVSS 3.x
7.4
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
7.4 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
ElasticsearchElastic7.0.0 (including)7.17.29 (including)
ElasticsearchElastic8.0.0 (including)8.19.8 (excluding)
ElasticsearchElastic9.0.0 (including)9.1.8 (excluding)
ElasticsearchElastic9.2.0 (including)9.2.2 (excluding)

Potential Mitigations

References