PT-2025-52371 · Elastic+1 · Kibana+1

Ismisepaul

+1

·

Published

2025-12-18

·

Updated

2026-02-24

·

CVE-2025-68386

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kibana (affected versions not specified)
Description An improper authorization issue exists in Kibana that can lead to privilege escalation. An authenticated user can modify a document's sharing type to "global" without the necessary permissions, making the document visible to all users within the Kibana space. This is achievable through a crafted HTTP request. The issue involves manipulating document sharing settings.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2026-00011
BIT-ELK-2025-68386
BIT-KIBANA-2025-68386
CVE-2025-68386

Affected Products

Kibana
Red Os