Home
MEDIUM: 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:NDefault status
unaffected
7.0.0 (semver)
affected
8.0.0 (semver)
affected
9.0.0 (semver)
affected
9.2.0 (semver)
affected
Description
Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.
Problem types
CWE-287 Improper Authentication
Product status
7.0.0 (semver)
8.0.0 (semver)
9.0.0 (semver)
9.2.0 (semver)
References
discuss.elastic.co/...2-2-security-update-esa-2025-27/384063
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.