CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2025-37727: Elasticsearch Insertion of sensitive information in log file

mediumCVSS 5.7CVE-2025-37727

CSIRTS triage

What
Elasticsearch logs sensitive information to files, exposing credentials or other confidential data.
Who is affected
All Elasticsearch deployments where logs may be accessible to unauthorized users.
Urgency
Medium severity (CVSS 5.7) information disclosure of logged secrets; patch promptly.
Action
Update Elasticsearch to a patched version and review log configuration and access controls.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Elasticsearch

Get an email when a new Elasticsearch advisory drops — max one per day, one-click unsubscribe.

Details

Source
Microsoft Security Response Center (INTL · vendor-psirt · site)
Severity
medium — CVSS 5.7
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync

Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-37727

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2025-37727coverage & exploitation statusNVD · CVE.org

More from Microsoft Security Response Center