CVE-2024-12556: Elastic Kibana
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal.
Affected products
- Elastic Kibana: from 8.16.1, before 8.16.4 (fixed in 8.16.4); from 8.17.0, before 8.17.2 (fixed in 8.17.2)
Published 2025-04-08. Last modified 2026-06-17.