CVE-2025-25010: Kibana privilege escalation via reporting_user role
Published Aug 28, 2025
·Updated
Incorrect authorization in Kibana can lead to privilege escalation via the built-in reportinguser role which incorrectly has the ability to access all Kibana Spaces.
Affected Software
3 affected components
Elastic Kibana
Elastic Kibana>=9.0.0<9.0.6
Elastic Kibana>=9.1.0<9.1.3
Remediation
Event History
Aug 28, 2025
CVE Published
via MITRE·03:52 PM
Data Sourced
via MITRE·03:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25010?
CVE-2025-25010 is considered a critical vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2025-25010?
To fix CVE-2025-25010, update Kibana to the latest patched version released by Elastic.
3
What causes the vulnerability in CVE-2025-25010?
CVE-2025-25010 is caused by incorrect authorization within Kibana, allowing the built-in reporting_user role excessive access.
4
Which versions of Kibana are affected by CVE-2025-25010?
CVE-2025-25010 affects various versions of Elastic Kibana where the reporting_user role is misconfigured.
5
What potential impact does CVE-2025-25010 have?
The impact of CVE-2025-25010 is significant, as it allows unauthorized users to access all Kibana Spaces, leading to data exposure.