Kibana Prototype Pollution Vulnerability Leading to Arbitrary Code Execution

Vulnerability

A prototype pollution vulnerability has been identified in Kibana, allowing for arbitrary code execution. This issue arises from crafted HTTP requests sent to Kibana's machine learning and reporting endpoints. The vulnerability affects Kibana versions 8.3.0 through 8.17.5, 8.18.0, and 9.0.0. It is present in both self-hosted and Elastic Cloud deployments where the machine learning and reporting features are enabled.

Impact

Exploitation of this vulnerability allows for arbitrary code execution within the Kibana environment. In Elastic Cloud deployments, this execution is confined to the Kibana Docker container, although it could potentially be escalated under certain conditions.

Remediation

Users should upgrade to Kibana versions 8.17.6, 8.18.1, or 9.0.1. For those unable to upgrade, self-hosted users can disable either the Machine Learning or Reporting features. On Elastic Cloud, users can disable the Reporting feature by modifying the Kibana user settings.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
10.0
exploitability
4.4
remediation
8.3
relevance
0.0
threat
0.1
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.