4.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Description
Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to bypass intended permission restrictions via a crafted HTTP request. This allows an attacker who lacks the live queries - read permission to successfully retrieve the list of live queries.
Basic Information
ID
CVE-2025-68422
Source
elastic
Published
Dec 18, 2025 at 22:32
Affected Product
Vendor
Elastic
Product
Kibana
Version
7.0.0
Affected Versions
Elastic Kibana 7.0.0
Elastic Kibana 8.0.0
Elastic Kibana 9.0.0
Elastic Kibana 9.2.0
Elastic Kibana 8.0.0
Elastic Kibana 9.0.0
Elastic Kibana 9.2.0