CVE-2025-68422: Kibana Improper Authorization
Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to bypass intended permission restrictions via a crafted HTTP request. This allows an attacker who lacks the live queries - read permission to successfully retrieve the list of live queries.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68422?
CVE-2025-68422 has been categorized as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-68422?
To fix CVE-2025-68422, update Kibana to the latest version where the vulnerability has been patched.
Who is affected by CVE-2025-68422?
CVE-2025-68422 affects all authenticated users of Kibana who may have inadequate permission restrictions.
What type of vulnerability is CVE-2025-68422?
CVE-2025-68422 is an improper authorization vulnerability classified under CWE-285.
What can an attacker achieve by exploiting CVE-2025-68422?
An attacker exploiting CVE-2025-68422 can bypass intended permission restrictions and gain unauthorized access to sensitive data.