{"id":"CVE-2025-25016","summary":"Kibana Unrestricted Upload of File","details":"Unrestricted file upload in Kibana allows an authenticated attacker to compromise software integrity by uploading a crafted malicious file due to insufficient server-side validation.","aliases":["BIT-elk-2025-25016","BIT-kibana-2025-25016"],"modified":"2026-08-12T15:13:23.035857Z","published":"2025-05-01T13:09:16.571Z","database_specific":{"cna_assigner":"elastic","cwe_ids":["CWE-434"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/25xxx/CVE-2025-25016.json"},"references":[{"type":"WEB","url":"https://discuss.elastic.co/t/kibana-7-17-19-and-8-13-0-security-update-esa-2024-47/377711"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/25xxx/CVE-2025-25016.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-25016"},{"type":"PACKAGE","url":"https://github.com/elastic/kibana"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/elasticsearch","events":[{"introduced":"bee86328705acaa9a6daede7140defd4d9ec56bd"},{"fixed":"92f290e9537478f85ff3fe3ab39945c1a49a6c1a"},{"introduced":"1b6a7ece17463df5ff54a3e1302d825889aa1161"},{"fixed":"09df99393193b2c53d92899662a8b8b3c55b45cd"}],"database_specific":{"cpe":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"7.17.0"},{"fixed":"7.17.19"},{"introduced":"8.0.0"},{"fixed":"8.13.0"}],"source":"CPE_RANGE"}},{"type":"GIT","repo":"https://github.com/elastic/kibana","events":[{"introduced":"60a9838d21b6420bbdb5a4d07099111b74c68ceb"},{"fixed":"c9d7ee0739b7d6af7553e326075e81728534ab44"},{"introduced":"57ca5e139a33dd2eed927ce98d8231a1f217cd15"},{"fixed":"2e3a5cd43e835baa1d596b1aa54735992259ecb9"}],"database_specific":{"extracted_events":[{"introduced":"7.17.0"},{"fixed":"7.17.19"},{"introduced":"8.0.0"},{"fixed":"8.13.0"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*"}}],"versions":["v7.17.18","v7.17.17","v7.17.16","v7.17.15","v7.17.14","v7.17.13","v7.17.12","v7.17.11","v7.17.10","v7.17.9","v7.17.8","v7.17.7","v7.17.6","v7.17.5","v7.17.4","v7.17.3","v7.17.2","v7.17.1","v7.17.0"],"database_specific":{"vanir_signatures_modified":"2026-08-12T15:13:23Z","vanir_signatures":[{"source":"https://github.com/elastic/elasticsearch/commit/92f290e9537478f85ff3fe3ab39945c1a49a6c1a","target":{"file":"server/src/internalClusterTest/java/org/elasticsearch/snapshots/SnapshotStressTestsIT.java"},"deprecated":false,"digest":{"line_hashes":["82047729086430910756604278104193458802","131410135016128987439099169873091096185","307499659489575771444191318791584808901","283573415662965770105778062442554353810","246118581985204571158009790777095832719","11882487284426012650628006900929671532"],"threshold":0.9},"id":"CVE-2025-25016-03f25105","signature_type":"Line","signature_version":"v1"},{"source":"https://github.com/elastic/elasticsearch/commit/92f290e9537478f85ff3fe3ab39945c1a49a6c1a","target":{"file":"server/src/internalClusterTest/java/org/elasticsearch/snapshots/SnapshotStressTestsIT.java","function":"startCleaner"},"deprecated":false,"digest":{"function_hash":"12158914231129088094406129298884796573","length":1180},"id":"CVE-2025-25016-939533c3","signature_type":"Function","signature_version":"v1"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/09df99393193b2c53d92899662a8b8b3c55b45cd","target":{"file":"server/src/test/java/org/elasticsearch/threadpool/ThreadPoolTests.java"},"deprecated":false,"digest":{"line_hashes":["36530912574437381226782567206995626327","244108005552100167940772669739727799311","122676380888478570388070130641794056358"],"threshold":0.9},"id":"CVE-2025-25016-9616b188"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-25016.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"}]}