Elastic Product Security Update Advisory (CVE-2025-25015)

Elastic Product Security Update Advisory (CVE-2025-25015)

Overview

We have released security updates to fix vulnerabilities in Elastic products. We encourage affected product users to update to the latest version.
 

 

Affected Products

 

CVE-2025-25015

Kibana versions: 8.15.0 through 8.17.3 (excluded)

 

 

Resolved Vulnerabilities

Arbitrary code execution vulnerability in Kibana (CVE-2025-25015)

 

 

Vulnerability Patches

Vulnerability patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
 

 

CVE-2025-25015

Kibana version: 8.17.3

 

 

References

[1] Kibana 8.17.3 Security Update (ESA-2025-06)
https://discuss.elastic.co/t/kibana-8-17-3-security-update-esa-2025-06/375441

[2] CVE-2025-25015 Details
https://nvd.nist.gov/vuln/detail/CVE-2025-25015

[3] Download Kibana
https://www.elastic.co/downloads/kibana