
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68389 is a denial-of-service vulnerability in Elastic Kibana caused by allocation of resources without limits or throttling (CWE-770). A low-privileged authenticated user can send a crafted HTTP request to trigger excessive allocation of computing resources, crashing the Kibana process. The vulnerability affects Kibana versions 7.0.0–7.17.29, 8.0.0–8.19.8, 9.0.0–9.1.8, and 9.2.0–9.2.2. It was disclosed on December 18, 2025, and carries a CVSS v3.1 base score of 6.5 (Medium) (Elastic Advisory, Red Hat Bugzilla).
The root cause is CWE-770 (Allocation of Resources Without Limits or Throttling), where Kibana fails to impose adequate constraints on resource consumption triggered by certain HTTP requests. An authenticated attacker with low privileges can craft a specific HTTP request that causes the Kibana server process to allocate excessive computing resources, consistent with CAPEC-130 (Excessive Allocation). No authentication bypass is required — only a valid low-privileged account is needed to exploit this flaw over the network with low attack complexity and no user interaction (Red Hat Bugzilla, Elastic Advisory).
Successful exploitation results in a denial-of-service condition, crashing or rendering the Kibana process unresponsive. This disrupts access to Kibana's monitoring, logging, and visualization capabilities for all legitimate users. There is no confidentiality or integrity impact — the vulnerability is limited to availability (CVSS A:H). In environments where Kibana is central to security operations or observability pipelines, an outage could impair incident detection and response capabilities (Elastic Advisory, Red Hat Bugzilla).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.20%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
Elastic has released patched versions addressing this vulnerability: Kibana 8.19.9, 9.1.9, and 9.2.3 (Elastic Advisory). Note that Kibana 7.x versions up to 7.17.29 are listed as affected; users on the 7.x branch should upgrade to a supported 8.x or 9.x release. As interim mitigations, administrators should restrict Kibana access to trusted users only, implement network-level rate limiting on the Kibana port, apply least-privilege principles to user accounts, and monitor for unusual resource consumption patterns.
The vulnerability was tracked by Red Hat's Product Security team via Bugzilla and assigned medium priority and severity (Red Hat Bugzilla). INCIBE-CERT (Spain's national cybersecurity agency) published an early warning advisory for the vulnerability. No significant public researcher commentary, social media discussion, or major media coverage has been identified beyond standard vulnerability database aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."