PT-2025-52372 · Elastic+1 · Kibana+1

Ismisepaul

+1

·

Published

2025-12-18

·

Updated

2026-02-24

·

CVE-2025-68422

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kibana (affected versions not specified)
Description An improper authorization issue exists in Kibana that could allow an authenticated user to bypass intended permission restrictions. Specifically, an attacker lacking the necessary permissions for live queries can retrieve a list of them through a crafted HTTP request. This can lead to privilege escalation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Incorrect Authorization

Improper Authorization

Weakness Enumeration

Related Identifiers

BDU:2026-00012
BIT-ELK-2025-68422
BIT-KIBANA-2025-68422
CVE-2025-68422

Affected Products

Kibana
Red Os