CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2025-37727

mediumCVSS 5.7covered by 1 sourcefirst seen 2026-08-06

CSIRTS triage

What
Elasticsearch logs sensitive information to files, exposing credentials or other confidential data.
Who is affected
All Elasticsearch deployments where logs may be accessible to unauthorized users.
Urgency
Medium severity (CVSS 5.7) information disclosure of logged secrets; patch promptly.
Action
Update Elasticsearch to a patched version and review log configuration and access controls.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2025-37727

Get an email if CVE-2025-37727 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2025-37727

CVE.org record

Embed the live status

CVE-2025-37727 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2025-37727 status](https://www.csirts.com/badge/CVE-2025-37727)](https://www.csirts.com/cve/CVE-2025-37727)