CVE-2024-12556: Elastic Kibana

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal.

Affected products

  • Elastic Kibana: from 8.16.1, before 8.16.4 (fixed in 8.16.4); from 8.17.0, before 8.17.2 (fixed in 8.17.2)

Published 2025-04-08. Last modified 2026-06-17.