Privilege Escalation Vulnerability in Kibana by Elastic
CVE-2025-25010

6.5MEDIUM

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
28 August 2025

What is CVE-2025-25010?

An authorization flaw in Kibana allows users assigned to the built-in reporting_user role to access all Kibana Spaces, which should be restricted. This misconfiguration can lead to unauthorized actions and data exposure, potentially impacting the integrity and confidentiality of user data across Kibana installations.

Affected Version(s)

Kibana 9.0.0 <= 9.0.5

Kibana 9.1.0 <= 9.1.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-25010 : Privilege Escalation Vulnerability in Kibana by Elastic