Vulnerability GHSA-m9gh-789g-q5pv

Medium Risk
MEDIUM RISK
CVSS Score: 6.8
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
9 months ago
December 15, 2025 at 12:30 PM UTC
Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates
7.8.1 and 7.12.0 - 8.0.1 and 8.7.0 - 8.7.1 and 9.2.0 - 9.2.1
7.8.1 and 7.12.0 - 8.0.1 and 8.7.0 - 8.7.1 and 9.2.0 - 9.2.1

Summary

Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates

Details

Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.

Timeline

Published
9 months ago
December 15, 2025 at 12:30 PM UTC
Fixed (8.19.8)
Unknown
Unknown
Fixed (9.1.8)
Unknown
Unknown
Fixed (9.2.2)
Unknown
Unknown
Fixed (8.19.8)
Unknown
Unknown
Fixed (9.1.8)
Unknown
Unknown
Fixed (9.2.2)
Unknown
Unknown
Last Modified
2 days ago
September 25, 2026 at 05:45 PM UTC