CVE-2025-25010
28.08.2025, 16:15
Incorrect authorization in Kibana can lead to privilege escalation via the built-in reporting_userrole which incorrectly has the ability to access all Kibana Spaces.Enginsight
Vendor | Product | Version |
---|---|---|
elastic | kibana | 9.0.0 ≤ 𝑥 < 9.0.6 |
elastic | kibana | 9.1.0 ≤ 𝑥 < 9.1.3 |
𝑥
= Vulnerable software versions