Elasticsearch Kibana Security Update – 09 March 2025

Elasticsearch has released a security update to a fix critical vulnerability affecting Kibana versions from 8.15.0 to 8.17.3.

The addressed vulnerability could allow the remote attacker to execute arbitrary code and gain access by uploading a crafted HTTP request.

Elasticsearch Kibana Remote Code Execution Vulnerability (CVE-2025-25015):

  • CVSS: 9.9
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities

CVE-2025-25015

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Elastic Security Advisory

References