📦 Kibana

by Elastic

🔍 What is Kibana?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-25014

CRITICAL CVSS 9.1 May 6, 2025

A prototype pollution vulnerability in Kibana allows attackers to execute arbitrary code by sending specially crafted HTTP requests to machine learning and reporting endpoints. This affects all Kibana...

CVE-2024-37285

CRITICAL CVSS 9.1 Nov 14, 2024

A deserialization vulnerability in Kibana allows authenticated attackers with specific Elasticsearch and Kibana privileges to execute arbitrary code by uploading malicious YAML documents. This affects...

CVE-2024-37288

CRITICAL CVSS 9.9 Sep 9, 2024

A deserialization vulnerability in Kibana allows arbitrary code execution when parsing malicious YAML documents. This only affects users who have enabled Elastic Security's built-in AI tools and confi...

CVE-2024-37287

CRITICAL CVSS 9.1 Aug 13, 2024

This CVE describes a prototype pollution vulnerability in Kibana that allows authenticated attackers with specific permissions to execute arbitrary code. It affects Kibana instances where users have M...

CVE-2023-31422

CRITICAL CVSS 9.0 Oct 26, 2023

Kibana 8.10.0 logs sensitive information like authentication credentials, cookies, and authorization headers in error logs when configured with JSON layout or %meta pattern. This vulnerability allows ...

CVE-2025-68385

HIGH CVSS 7.2 Dec 18, 2025

This CVE describes a cross-site scripting (XSS) vulnerability in Vega visualization components that allows authenticated users to inject malicious scripts into web content. The vulnerability bypasses ...

CVE-2025-25018

HIGH CVSS 8.7 Oct 10, 2025

This vulnerability in Kibana allows attackers to inject malicious scripts into web pages through improper input neutralization, leading to stored cross-site scripting (XSS). When exploited, it enables...

CVE-2025-25017

HIGH CVSS 8.2 Oct 10, 2025

This CVE describes a cross-site scripting (XSS) vulnerability in Kibana where improper input sanitization during web page generation allows attackers to inject malicious scripts. The vulnerability aff...

CVE-2024-43706

HIGH CVSS 7.6 Jun 10, 2025

This CVE describes an improper authorization vulnerability in Kibana's Synthetic monitor endpoint that allows authenticated users to perform unauthorized actions via direct HTTP requests. It affects K...

CVE-2024-12556

HIGH CVSS 8.7 Apr 8, 2025

This vulnerability allows attackers to exploit prototype pollution in Kibana to achieve code injection by combining unrestricted file upload with path traversal. It affects Kibana instances with vulne...

CVE-2024-43707

HIGH CVSS 7.7 Jan 23, 2025

This CVE describes an information disclosure vulnerability in Kibana where users without Fleet privileges can view Elastic Agent policies that may contain sensitive data. The vulnerability affects Kib...

CVE-2023-46671

HIGH CVSS 8.0 Dec 13, 2023

This vulnerability in Kibana logs sensitive credentials like kibana_system user passwords, API keys, and end-user credentials when specific errors occur during Elasticsearch cluster interactions. It a...

CVE-2023-31414

HIGH CVSS 8.8 May 4, 2023

CVE-2023-31414 allows arbitrary code execution in Kibana when an attacker with write access to configuration files injects malicious JavaScript payloads. This vulnerability affects Kibana versions 8.0...

CVE-2026-0528

MEDIUM CVSS 6.5 Jan 13, 2026

This CVE describes two denial-of-service vulnerabilities in Metricbeat where specially crafted payloads sent to Graphite or Zookeeper metricsets, or malformed metric data sent to the Prometheus helper...

CVE-2026-0530

MEDIUM CVSS 6.5 Jan 13, 2026

This vulnerability in Kibana Fleet allows attackers to send specially crafted requests that cause excessive resource allocation, leading to service degradation or complete unavailability through resou...

CVE-2026-0531

MEDIUM CVSS 6.5 Jan 13, 2026

CVE-2026-0531 is a resource exhaustion vulnerability in Kibana Fleet where specially crafted bulk retrieval requests can cause excessive memory consumption leading to server crashes. Attackers with vi...

CVE-2025-68386

MEDIUM CVSS 4.3 Dec 18, 2025

This vulnerability allows authenticated Kibana users to escalate privileges by changing document sharing settings to 'global', making documents visible to all users in a space. It affects Kibana insta...

CVE-2025-68387

MEDIUM CVSS 6.1 Dec 18, 2025

This CVE describes a cross-site scripting (XSS) vulnerability in Kibana's Vega AST evaluator that allows unauthenticated attackers to inject malicious scripts into web pages. When exploited, these scr...

CVE-2025-68389

MEDIUM CVSS 6.5 Dec 18, 2025

This vulnerability allows authenticated Kibana users with low privileges to send crafted HTTP requests that cause excessive resource allocation, leading to denial of service. It affects Kibana instanc...

CVE-2025-68422

MEDIUM CVSS 4.3 Dec 18, 2025

CVE-2025-68422 is an improper authorization vulnerability in Kibana that allows authenticated users to bypass permission restrictions via crafted HTTP requests. This enables attackers without 'live qu...

CVE-2025-37732

MEDIUM CVSS 5.4 Dec 15, 2025

This CVE describes a cross-site scripting (XSS) vulnerability in Kibana's integration package upload functionality that allows authenticated users to inject HTML into other users' browsers. It affects...

CVE-2025-37734

MEDIUM CVSS 4.3 Nov 12, 2025

An origin validation error in Kibana's Observability AI Assistant allows attackers to perform Server-Side Request Forgery (SSRF) by forging the Origin HTTP header. This vulnerability affects Kibana in...

CVE-2025-25010

MEDIUM CVSS 6.5 Aug 28, 2025

This CVE describes an incorrect authorization vulnerability in Kibana where the built-in reporting_user role has excessive permissions, allowing it to access all Kibana Spaces. This enables privilege ...

CVE-2024-11390

MEDIUM CVSS 5.4 May 1, 2025

This vulnerability allows attackers to upload malicious HTML/JavaScript files through Kibana's Synthetics app, leading to cross-site scripting (XSS) attacks. Users with access to the Synthetics app or...

CVE-2024-43708

MEDIUM CVSS 6.5 Jan 23, 2025

This vulnerability allows authenticated users with read access to Kibana to send specially crafted payloads that cause resource exhaustion, leading to Kibana service crashes. It affects Kibana instanc...

CVE-2024-43710

MEDIUM CVSS 4.3 Jan 23, 2025

A server-side request forgery (SSRF) vulnerability in Kibana's Fleet API allows authenticated users with read access to send requests to internal HTTPS endpoints that return JSON. This could expose in...

CVE-2024-23443

MEDIUM CVSS 4.9 Jun 19, 2024

This vulnerability allows high-privileged Kibana users with osquery pack creation permissions to upload malicious packs that could cause Kibana availability issues through resource exhaustion. It affe...

CVE-2024-23442

MEDIUM CVSS 6.1 Jun 14, 2024

This CVE describes an open redirect vulnerability in Kibana where attackers can craft malicious URLs that redirect users to arbitrary external websites. Kibana users who click on specially crafted lin...

CVE-2024-37279

MEDIUM CVSS 4.3 Jun 13, 2024

This vulnerability allows view-only users in Kibana to abuse the run_soon API to trigger continuous execution of alerting rules. This could lead to resource exhaustion and system availability issues i...