CVE-2025-25014
largePrototype Pollution RCE in Elastic Kibana ML and Reporting Endpoints
CVE-2025-25014 is a prototype pollution flaw (CWE-1321) in Elastic Kibana that can lead to arbitrary code execution when an attacker sends crafted HTTP requests to the machine learning and reporting endpoints. The CVSS vector (AV:N/PR:N/UI:N) indicates the attack path requires no privileges or user interaction, so a network-reachable attacker can potentially execute code in the context of the Kibana process. Any organization running a vulnerable Kibana build is affected — especially deployments that expose Kibana's HTTP interface to the internet or untrusted networks — with exact affected version ranges to be confirmed in Elastic's advisory. There is currently no confirmed in-the-wild exploitation, no public proof-of-concept, and the issue is not in CISA's KEV, but EPSS assigns a relatively high 21.5% probability of exploitation within 30 days (97th percentile).
What to do: Upgrade Kibana to the patched release specified in Elastic's security advisory (the provided data does not include version numbers). Until patched, restrict network access to Kibana's HTTP interface, particularly the machine learning and reporting endpoints, and avoid exposing Kibana directly to the internet. Review HTTP access logs for suspicious requests targeting ML/reporting routes and watch for an upcoming public PoC given the elevated EPSS score.
| Elastic Kibana | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.
- Vendors
- elastic
- Products
- kibana
- Weakness
- CWE-1321
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H