Privilege Escalation Vulnerability in Kibana by Elastic
CVE-2025-25010
6.5MEDIUM
What is CVE-2025-25010?
An authorization flaw in Kibana allows users assigned to the built-in reporting_user role to access all Kibana Spaces, which should be restricted. This misconfiguration can lead to unauthorized actions and data exposure, potentially impacting the integrity and confidentiality of user data across Kibana installations.
Affected Version(s)
Kibana 9.0.0 <= 9.0.5
Kibana 9.1.0 <= 9.1.2