PT-2025-19890 · Kibana+1 · Kibana

·

CVE-2025-25014

·

Published

2025-05-06

·

Updated

2026-08-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kibana versions 8.3.0 through 8.17.5 Kibana version 8.18.0
Description A prototype pollution flaw allows remote attackers to achieve arbitrary code execution. This occurs when the software fails to properly control the modification of object prototype attributes. The issue is triggered by sending specially crafted HTTP requests to the machine learning and reporting endpoints. Prototype pollution is a technique where an attacker manipulates the base prototype of an object to inject properties that can alter the behavior of the application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

RCE

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-05298
BIT-ELK-2025-25014
BIT-KIBANA-2025-25014
CVE-2025-25014

Affected Products

Kibana