Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests. In Kibana versions >= 8.15.0 and < 8.17.1, this is exploitable by users with the Viewer role. In Kibana versions 8.17.1 and 8.17.2 , this is only exploitable by users that have roles that contain all the following privileges: fleet-all, integrations-all, actions:execute-advanced-connectors
Conclusion & alert: CVE-2025-25015 is rated High Risk (65.1/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 0.74%). Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-25 | 0.76% | 0.74% | -0.02% |
| 2 | 2026-04-21 | 0.65% | 0.76% | +0.11% |
| 3 | 2026-04-13 | — | 0.65% | — |
Full EPSS history (19 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.9 | 3.1 | CRITICAL |
|
3.1 | 6.0 | [email protected] |
| URL | Tags |
|---|---|
| https://discuss.elastic.co/t/kibana-8-17-3-8-16-6-security-update-esa-2025-06/375441 | Mitigation Vendor Advisory |