PT-2025-9909 · Elastic · Kibana

Published

2025-03-06

·

Updated

2025-09-30

·

CVE-2025-25012

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Elastic Kibana versions 8.15.0 through 8.17.2
Description A critical code execution vulnerability has been discovered in Elastic Kibana, allowing remote code execution. This issue affects versions 8.15.0 to 8.17.2, with specific roles being highly vulnerable. The vulnerability is related to prototype pollution within Kibana's file upload handler and HTTP request processing. With a high severity score, it poses a serious risk, giving authenticated attackers the ability to execute arbitrary code on systems where Kibana is implemented. The implications of this vulnerability range from unauthorized data access to full system compromise. It is estimated that over 379,900 services are potentially affected.
Recommendations To resolve the issue for Elastic Kibana versions 8.15.0 through 8.17.2, upgrade to version 8.17.3 as soon as possible. For versions where an immediate upgrade is not possible, add the parameter xpack.integration assistant.enabled: false to the Kibana configuration to mitigate the risk.

Fix

RCE

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ELK-2025-25012
BIT-KIBANA-2025-25012
CVE-2025-25012

Affected Products

Kibana