Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-m9gh-789g-q5pv | Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates |
Fri, 27 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Thu, 18 Dec 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:* |
Wed, 17 Dec 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 15 Dec 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Elastic
Elastic elasticsearch |
|
| Vendors & Products |
Elastic
Elastic elasticsearch |
|
| Metrics |
ssvc
|
Mon, 15 Dec 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority. | |
| Title | Elasticsearch Improper Authentication | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-02-26T16:07:40.327Z
Reserved: 2025-04-16T03:24:04.511Z
Link: CVE-2025-37731
Updated: 2025-12-15T13:12:22.535Z
Status : Analyzed
Published: 2025-12-15T11:15:39.707
Modified: 2025-12-18T01:49:07.083
Link: CVE-2025-37731
OpenCVE Enrichment
Updated: 2025-12-15T14:05:33Z
Github GHSA