PT-2025-9821 · Elastic · Kibana

Ikakavas

+1

·

Published

2025-03-05

·

Updated

2026-05-28

·

CVE-2025-25015

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kibana versions 8.15.0 through 8.17.2
Description Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests. In Kibana versions >= 8.15.0 and < 8.17.1, this is exploitable by users with the Viewer role. In Kibana versions 8.17.1 and 8.17.2, this is only exploitable by users that have roles that contain all the following privileges: fleet-all, integrations-all, actions:execute-advanced-connectors. Over 198,000 exposed instances have been spotted.
Recommendations For Kibana versions 8.15.0 through 8.17.2, update to version 8.17.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable module and limiting user privileges to minimize the risk of exploitation. Avoid using crafted file uploads and HTTP requests until the issue is resolved.

Fix

RCE

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-02369
BIT-ELK-2025-25015
BIT-KIBANA-2025-25015
CVE-2025-25015

Affected Products

Kibana