Skip to content
ElasticsearchGHSA-m9gh-789g-q5pv

Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates

Medium6.8CVE-2025-37731 · Published Dec 15, 2025 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
org.elasticsearch:elasticsearch
Maven
>= 7.0.0-alpha1, < 8.19.88.19.8
>= 9.0.0-beta1, < 9.1.89.1.8
>= 9.2.0, < 9.2.29.2.2
Details and references

Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-287, CWE-295
Also known as
BIT-elasticsearch-2025-37731, CVE-2025-37731

More Elasticsearch advisories

All Elasticsearch
DateAdvisory
Oct 102025Elasticsearch: Insertion of Sensitive Information into Log File via reindex API
CVE-2025-37727Medium5.7fixed in 8.18.8, 8.19.5, 9.0.8, 9.1.5
May 12025Elasticsearch Uncontrolled Resource Consumption Vulnerability
CVE-2024-52979Medium6.5fixed in 7.17.25, 8.16.0
Apr 82025Elasticsearch Vulnerable to Stack Overflow due to a Large Recursion
CVE-2024-52981Medium4.9fixed in 7.17.24, 8.15.1
Apr 82025Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
CVE-2024-52980Medium6.5fixed in 8.15.1
Jan 212025Elasticsearch allocation of resources without limits or throttling leads to crash
CVE-2024-43709Medium6.5fixed in 7.17.21, 8.13.3
Dec 172024Elasticsearch Incorrect Authorization vulnerability
CVE-2024-12539Mediumfixed in 8.16.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.