CVE-2025-25010

Publication date

2025-08-28 15:52:08

Family

elastic

State

PUBLISHED

Description

Incorrect authorization in Kibana can lead to privilege escalation via the built-in reporting_user role which incorrectly has the ability to access all Kibana Spaces.