CVE-2024-37287: Elastic Kibana
High severity, CVSS 7.2. EPSS: 1.6% chance of exploitation in the next 30 days.
A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML and Alerting connector features, as well as write access to internal ML indices can trigger a prototype pollution vulnerability, ultimately leading to arbitrary code execution.
Affected products
- Elastic Kibana: from 7.7.0, before 7.17.23 (fixed in 7.17.23); from 8.0.0, before 8.14.2 (fixed in 8.14.2)
Published 2024-08-13. Last modified 2026-06-17.