VYPR
Unrated severityOSV Advisory· Published Dec 18, 2025· Updated Dec 19, 2025

Kibana Improper Authorization

CVE-2025-68422

Description

Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to bypass intended permission restrictions via a crafted HTTP request. This allows an attacker who lacks the live queries - read permission to successfully retrieve the list of live queries.

Affected products

1
  • Range: 7.0-known-good, deploy@1693594780, deploy@1693609987, …

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.