CVE-2025-37731Medium· 6.8▾ SunlitElasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.2%
Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.
org.elasticsearch.plugin:x-pack-security >= 7.0.0-alpha1, < 8.19.8org.elasticsearch.plugin:x-pack-security >= 9.0.0-beta1, < 9.1.8org.elasticsearch.plugin:x-pack-security >= 9.2.0, < 9.2.2org.elasticsearch.plugin:x-pack-core >= 7.0.0-alpha1, < 8.19.8org.elasticsearch.plugin:x-pack-core >= 9.0.0-beta1, < 9.1.8org.elasticsearch.plugin:x-pack-core >= 9.2.0, < 9.2.2Upgrade to a patched release:
org.elasticsearch.plugin:x-pack-security 8.19.8org.elasticsearch.plugin:x-pack-security 9.1.8org.elasticsearch.plugin:x-pack-security 9.2.2org.elasticsearch.plugin:x-pack-core 8.19.8org.elasticsearch.plugin:x-pack-core 9.1.8org.elasticsearch.plugin:x-pack-core 9.2.2Connected by shared product, vendor, weakness, or advisory.
CVE-2024-52980Medium· 6.5Elasticsearch-grok Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
CVE-2025-64432Medium· 4.7KubeVirt is a virtual machine management add-on for Kubernetes
CVE-2023-49105Critical· 9.8An issue was discovered in ownCloud owncloud/core before 10.13.1
CVE-2019-1946Medium· 6.5A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and get limited access to the web-based management int…
CVE-2020-12812Critical· 9.8An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if t…
CVE-2022-40684Critical· 9.8An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 …