Vulnerability Intelligence Report
Kibana arbitrary code execution via prototype pollution
CVE-2025-25015
Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests. In Kibana versions >= 8.15.0 and < 8.17.1, this is exploitable by users with the Viewer role. In Kibana versions 8.17.1 and 8.17.2 , this is only exploitable by users that have roles that contain all the following privileges: fleet-all, integrations-all, actions:execute-advanced-connectors
No Active Exploit Signals
CVSS Base Score
9.9
CRITICAL
Exploitability:3.2
Impact Score:6.1
EPSS Probability:1.22%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-1321 ↗CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Elastic | Kibana | 8.15.0 < 8.16.6 (affected), 8.17.0 < 8.17.3 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.218%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Elastic · Vendor · Netherlands |
| Reserved | 2025-01-31T15:28:16 |
| Published | 2025-03-05T09:46:34 |
| Patch Date | 2025-03-05 |
| Last Updated | 2026-02-26T19:09:45 |
Community Chatter & Buzz