Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.security.audit.enabled set to true, an attacker could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
CVSS Details
- CVSS 3.1 Base Score: 9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Mar 25, 2019 | |
| Elastic Kibana | elastic-kibana-upgrade-latest | Sep 3, 2025 | Mar 25, 2019 | |
| Redhat Openshift | linuxrpm-upgrade-kibana | Oct 8, 2019 | Mar 25, 2019 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Mar 25, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub