
Elastic Releases Security Updates to Fix Critical Vulnerability in Kibana
CybersecurityVulnerabilitiesSoftwareUpdatesRemoteCodeExecution
Elastic has released security updates to address a critical vulnerability affecting Kibana, the data visualization dashboard software for Elasticsearch. This flaw, listed under the number CVE-2025-25015, has a CVSS score of 9.9 out of 10. It is described as a case of prototype pollution. Prototype pollution in Kibana can allow remote code execution.