logo

Elastic Fixes Multiple High-Severity Vulnerabilities in Kibana and Elasticsearch

ID: 21b73658-1686-5cab-979a-fdd72120554c

STIX ID: report--21b73658-1686-5cab-979a-fdd72120554c

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2025-10-07

Date Updated: 2026-04-22

Author: Ddos

...
...

Elastic published advisories for five vulnerabilities in Kibana and Elasticsearch—three high-severity stored XSS flaws that can lead to data theft or session hijacking (notably CVE-2025-25009, CVE-2025-25017, CVE-2025-25018) and two information/credential disclosure issues in Elasticsearch audit logging and the CrowdStrike connector (CVE-2025-37727, CVE-2025-37728). Affected versions include Kibana ≤7.17.29 and up through 9.1.4; fixes are available in 8.18.8, 8.19.5, 9.0.8, and 9.1.5, with recommended mitigations for environments that cannot immediately upgrade.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.