CVE-2025-25016: Elastic Kibana
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Unrestricted file upload in Kibana allows an authenticated attacker to compromise software integrity by uploading a crafted malicious file due to insufficient server-side validation.
Affected products
- Elastic Kibana: from 7.17.0, before 7.17.19 (fixed in 7.17.19); from 8.0.0, before 8.13.0 (fixed in 8.13.0)
Published 2025-05-01. Last modified 2026-06-17.