Medium severity6.5NVD Advisory· Published Aug 28, 2025· Updated Jun 17, 2026
CVE-2025-25010
CVE-2025-25010
Description
Incorrect authorization in Kibana can lead to privilege escalation via the built-in reporting_user role which incorrectly has the ability to access all Kibana Spaces.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- osv-coords2 versions
>= 9.0.0, < 9.0.6+ 1 more
- (no CPE)range: >= 9.0.0, < 9.0.6
- (no CPE)range: >= 9.0.0, < 9.0.6
Patches
Vulnerability mechanics
References
1- discuss.elastic.co/t/kibana-9-0-6-9-1-3-security-update-esa-2025-13/381426nvdIssue TrackingPatchVendor Advisory
News mentions
0No linked articles in our index yet.