Home
CRITICAL: 9.1 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HDefault status
unaffected
8.3.0 (semver) before 8.17.6
affected
8.18.0 (semver) before 8.18.1
affected
9.0.0 (semver) before 9.0.1
affected
Description
A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.
Problem types
Product status
8.3.0 (semver) before 8.17.6
8.18.0 (semver) before 8.18.1
9.0.0 (semver) before 9.0.1
References
discuss.elastic.co/...0-1-security-update-esa-2025-07/377868