Improper Authorization Vulnerability in Kibana by Elastic
CVE-2025-68422
4.3MEDIUM
What is CVE-2025-68422?
An improper authorization flaw in Kibana allows authenticated users to exploit permission restrictions by sending a specially crafted HTTP request. This vulnerability enables an attacker without the necessary live queries - read permission to access and retrieve a list of live queries, potentially leading to unauthorized disclosure of sensitive information. Organizations using affected versions of Kibana should prioritize applying the latest security updates to mitigate this risk.
Affected Version(s)
Kibana 7.0.0 <= 7.17.29
Kibana 8.0.0 <= 8.19.6
Kibana 9.0.0 <= 9.1.6