CVE-2025-25014: Elastic Kibana

Critical severity, CVSS 9.8. EPSS: 22.2% chance of exploitation in the next 30 days.

A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.

Affected products

  • Elastic Kibana: from 8.3.0, before 8.17.6 (fixed in 8.17.6); version 8.18.0 only; version 9.0.0 only

Published 2025-05-06. Last modified 2026-06-17.