VYPR
Unrated severityNVD Advisory· Published Aug 28, 2025· Updated Feb 26, 2026

Kibana privilege escalation via reporting_user role

CVE-2025-25010

Description

Incorrect authorization in Kibana can lead to privilege escalation via the built-in reporting_user role which incorrectly has the ability to access all Kibana Spaces.

Affected products

2
  • Elastic/Kibanallm-fuzzy2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 9.0.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.