← Back to CVE List
Vulnerability Intelligence Report
Kibana arbitrary code execution via prototype pollution

CVE-2025-25015

Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests. In Kibana versions >= 8.15.0 and < 8.17.1, this is exploitable by users with the Viewer role. In Kibana versions 8.17.1 and 8.17.2 , this is only exploitable by users that have roles that contain all the following privileges: fleet-all, integrations-all, actions:execute-advanced-connectors

No Active Exploit Signals
CVSS Base Score
9.9
CRITICAL
Exploitability:3.2
Impact Score:6.1
EPSS Probability:1.22%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-1321 ↗CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Affected Products & Versions

Vendor Product Affected Versions
Elastic Kibana 8.15.0 < 8.16.6 (affected), 8.17.0 < 8.17.3 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.218%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityElastic · Vendor · Netherlands
Reserved2025-01-31T15:28:16
Published2025-03-05T09:46:34
Patch Date2025-03-05
Last Updated2026-02-26T19:09:45

LINK COPIED TO CLIPBOARD