Elastic disclosed and patched several high-severity cross-site scripting flaws in Kibana that could let authenticated attackers plant malicious JavaScript and trigger it when other users open affected interfaces. The issues include CVE-2025-25018 in Fleet and Integrations management, CVE-2025-25009 in case-management file uploads, and CVE-2025-25017 in Vega visualizations and dashboards. Successful exploitation could enable session hijacking, credential or data theft from the Kibana interface, unauthorized Kibana API actions, and possible privilege escalation if a more privileged user views the malicious content.
Elastic released fixes in Kibana 8.18.8, 8.19.5, 9.0.8, and 9.1.5, and earlier security updates were also issued through advisory ESA-2025-06 for the 8.17.3 and 8.16.6 branches. Temporary mitigations vary by flaw: organizations can restrict roles with All permissions for Fleet and Integrations to reduce exposure to CVE-2025-25018, enable the advanced setting discover:searchFieldsFromSource: true as a workaround for CVE-2025-25009 on Kibana 7.12 through 8.19.0, and disable Vega where immediate patching is not possible for CVE-2025-25017.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Elastic disclosed CVE-2025-25018, a stored XSS vulnerability in Kibana's Fleet and Integrations management interface caused by improper neutralization of user input. Exploitation requires a user with 'All' permissions under Management for Fleet and Integrations and can lead to session hijacking, data exfiltration, and possible privilege escalation.
Elastic disclosed CVE-2025-25017, an XSS vulnerability in Kibana's Vega visualization engine that can be triggered when a victim views a crafted Vega visualization. The issue can enable session hijacking, credential theft, and unauthorized Kibana API actions.
Elastic released patched Kibana versions 8.18.8, 8.19.5, 9.0.8, and 9.1.5 to address multiple XSS issues, including CVE-2025-25017, CVE-2025-25018, and CVE-2025-25009. The advisories also recommended mitigations such as restricting Fleet permissions or disabling Vega where immediate patching was not possible.
Elastic disclosed CVE-2025-25009, a stored XSS vulnerability in Kibana's case management file upload functionality that can execute malicious JavaScript when another user views an affected case. Elastic also released fixes in Kibana 8.18.8, 8.19.5, 9.0.8, and 9.1.5, and noted a temporary workaround for versions 7.12 through 8.19.0.
Elastic published the Kibana 7.17.19 and 8.13.0 security update advisory ESA-2024-47. The reference metadata explicitly anchors the advisory publication to 2025-05-01.
Elastic published the Kibana 8.17.3 / 8.16.6 security update advisory ESA-2025-06. The reference explicitly anchors this advisory publication to March 5, 2025.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
zeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcediscuss.elastic.co
Open sourcediscuss.elastic.co
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.