Improper Authorization Vulnerability in Kibana by Elastic
CVE-2025-68422

4.3MEDIUM

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
18 December 2025

What is CVE-2025-68422?

An improper authorization flaw in Kibana allows authenticated users to exploit permission restrictions by sending a specially crafted HTTP request. This vulnerability enables an attacker without the necessary live queries - read permission to access and retrieve a list of live queries, potentially leading to unauthorized disclosure of sensitive information. Organizations using affected versions of Kibana should prioritize applying the latest security updates to mitigate this risk.

Affected Version(s)

Kibana 7.0.0 <= 7.17.29

Kibana 8.0.0 <= 8.19.6

Kibana 9.0.0 <= 9.1.6

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-68422 : Improper Authorization Vulnerability in Kibana by Elastic