ZeroHour

CVE-2025-25014

large

Prototype Pollution RCE in Elastic Kibana ML and Reporting Endpoints

CVSS 3.1
9.8 critical
EPSS
21%p97
Published
()
Modified
AI analysis

CVE-2025-25014 is a prototype pollution flaw (CWE-1321) in Elastic Kibana that can lead to arbitrary code execution when an attacker sends crafted HTTP requests to the machine learning and reporting endpoints. The CVSS vector (AV:N/PR:N/UI:N) indicates the attack path requires no privileges or user interaction, so a network-reachable attacker can potentially execute code in the context of the Kibana process. Any organization running a vulnerable Kibana build is affected — especially deployments that expose Kibana's HTTP interface to the internet or untrusted networks — with exact affected version ranges to be confirmed in Elastic's advisory. There is currently no confirmed in-the-wild exploitation, no public proof-of-concept, and the issue is not in CISA's KEV, but EPSS assigns a relatively high 21.5% probability of exploitation within 30 days (97th percentile).

What to do: Upgrade Kibana to the patched release specified in Elastic's security advisory (the provided data does not include version numbers). Until patched, restrict network access to Kibana's HTTP interface, particularly the machine learning and reporting endpoints, and avoid exposing Kibana directly to the internet. Review HTTP access logs for suspicious requests targeting ML/reporting routes and watch for an upcoming public PoC given the elevated EPSS score.

Affected
Elastic Kibana
Estimated exposure
largetens of thousands of internet-exposed Kibana instances (public scan data), with far more internal/privately-hosted deployments — Public internet scans such as Shodan typically index on the order of tens of thousands of Kibana instances, and since Kibana ships with virtually every Elastic Stack deployment, total installations (including private networks) are likely…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.

Vendors
elastic
Products
kibana
Weakness
CWE-1321
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news