4.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Description
Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to change a document's sharing type to "global," even though they do not have permission to do so, making it visible to everyone in the space via a crafted a HTTP request.
Basic Information
ID
CVE-2025-68386
Source
elastic
Published
Dec 18, 2025 at 22:21
Affected Product
Vendor
Elastic
Product
Kibana
Version
7.0.0
Affected Versions
Elastic Kibana 7.0.0
Elastic Kibana 8.0.0
Elastic Kibana 9.0.0
Elastic Kibana 9.2.0
Elastic Kibana 8.0.0
Elastic Kibana 9.0.0
Elastic Kibana 9.2.0