CVE-2025-25016: Elastic Kibana

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Unrestricted file upload in Kibana allows an authenticated attacker to compromise software integrity by uploading a crafted malicious file due to insufficient server-side validation.

Affected products

  • Elastic Kibana: from 7.17.0, before 7.17.19 (fixed in 7.17.19); from 8.0.0, before 8.13.0 (fixed in 8.13.0)

Published 2025-05-01. Last modified 2026-06-17.