Elasticsearch Kibana Security Update – 07 May 2025

Elasticsearch has released a security update to a fix critical vulnerability affecting Kibana versions from 8.3.0 to 8.17.5, 8.18.0, and 9.0.0.

The addressed vulnerability could allow the remote attacker to execute arbitrary code and gain access to the affected product by uploading a crafted HTTP request.

Kibana Code Execution Vulnerability via Prototype Pollution (CVE-2025-25014):

  • CVSS: 9.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities

CVE-2025-25014

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Elastic Security Advisory

References