CVE-2025-68422: Elastic Kibana

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to bypass intended permission restrictions via a crafted HTTP request. This allows an attacker who lacks the live queries - read permission to successfully retrieve the list of live queries.

Affected products

  • Elastic Kibana: from 7.0.0, up to and including 7.17.29; from 8.0.0, before 8.19.7 (fixed in 8.19.7); from 9.0.0, before 9.1.7 (fixed in 9.1.7); version 9.2.0 only

Published 2025-12-18. Last modified 2026-06-17.