{"id":"CVE-2025-68422","summary":"Kibana Improper Authorization","details":"Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to bypass intended permission restrictions via a crafted HTTP request. This allows an attacker who lacks the live queries - read permission to successfully retrieve the list of live queries.","aliases":["BIT-elk-2025-68422","BIT-kibana-2025-68422"],"modified":"2026-08-12T15:14:51.825943Z","published":"2025-12-18T22:32:17.341Z","related":["CGA-p9h8-ff2v-6c79"],"database_specific":{"cna_assigner":"elastic","cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68422.json","unresolved_ranges":[{"extracted_events":[{"introduced":"7.0.0"},{"last_affected":"7.17.29"},{"introduced":"8.0.0"},{"last_affected":"8.19.6"},{"introduced":"9.0.0"},{"last_affected":"9.1.6"},{"introduced":"9.2.0"},{"last_affected":"9.2.0"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://discuss.elastic.co/t/kibana-8-19-7-9-1-7-and-9-2-1-security-update-esa-2025-39/384187"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68422.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68422"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/elasticsearch","events":[{"introduced":"b7e28a7232616c7a21bc879a535d801b8553ba77"},{"last_affected":"580aff1a0064ce4c93293aaab6fcc55e22c10d1c"},{"introduced":"1b6a7ece17463df5ff54a3e1302d825889aa1161"},{"fixed":"198d86868932741b4e0d184425510217febc27d1"},{"introduced":"112859b85d50de2a7e63f73c8fc70b99eea24291"},{"fixed":"49e091e266fdfecd2b3a96f9d390719838fb742d"},{"introduced":"25d88452371273dd27356c98598287b669a03eae"},{"last_affected":"25d88452371273dd27356c98598287b669a03eae"}],"database_specific":{"cpe":["cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","cpe:2.3:a:elastic:kibana:9.2.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.0.0"},{"last_affected":"7.17.29"},{"introduced":"8.0.0"},{"fixed":"8.19.7"},{"introduced":"9.0.0"},{"fixed":"9.1.7"},{"introduced":"9.2.0"},{"last_affected":"9.2.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["9.2.0","v9.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68422.json","vanir_signatures_modified":"2026-08-12T15:14:51Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/198d86868932741b4e0d184425510217febc27d1","target":{"file":"x-pack/plugin/transform/qa/single-node-tests/src/javaRestTest/java/org/elasticsearch/xpack/transform/integration/TransformPivotRestIT.java"},"deprecated":false,"digest":{"line_hashes":["87973156245404004901157156197252476295","317301723513968645256735115182799239909","34483913267341345077734435543786141146","96430500502949260309981307877992601785","127518069945181260477538726763075744704","219337533429638017097475052148675132976","420531683640021358963488244351018441","227583903981385669652097563859624396268","329341308206552947868896370615104826051","54380763793061404957457997079793096729","257131606868264344209252935558899424447"],"threshold":0.9},"id":"CVE-2025-68422-02111b81","signature_type":"Line"},{"target":{"file":"x-pack/plugin/transform/src/main/java/org/elasticsearch/xpack/transform/transforms/pivot/AggregationResultUtils.java","function":"value"},"deprecated":false,"digest":{"function_hash":"244227877865042808261390982377746257537","length":641},"id":"CVE-2025-68422-1dbb4604","signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/198d86868932741b4e0d184425510217febc27d1"},{"deprecated":false,"digest":{"line_hashes":["709843642339146015468947825752612345","52503817861039737041756639012120089787","318690857755301201023824454478332786821","129113998543793770165379391235766623996"],"threshold":0.9},"id":"CVE-2025-68422-4c1779e9","signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/198d86868932741b4e0d184425510217febc27d1","target":{"file":"x-pack/plugin/transform/src/main/java/org/elasticsearch/xpack/transform/transforms/pivot/AggregationResultUtils.java"}}]}},{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/kibana","events":[{"introduced":"ee89fda8a17eff9c93f7400c102edf76cb4d7d8a"},{"last_affected":"f6e2f2e44cc0a6a11435f1b6350f735e23bef4b4"},{"introduced":"57ca5e139a33dd2eed927ce98d8231a1f217cd15"},{"fixed":"28cf679904329ed50de370ff1e1e71f1b57996a1"},{"introduced":"504d6bfa94cca17fabb76e06152c30c4f0c3efdd"},{"fixed":"6c427d979e2b3a65eea87f31ba4b65dc579ee2f0"},{"introduced":"68626ce831ffb8e4138bb24ba8762a15a569a41c"},{"last_affected":"68626ce831ffb8e4138bb24ba8762a15a569a41c"}],"database_specific":{"cpe":["cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","cpe:2.3:a:elastic:kibana:9.2.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.0.0"},{"last_affected":"7.17.29"},{"introduced":"8.0.0"},{"fixed":"8.19.7"},{"introduced":"9.0.0"},{"fixed":"9.1.7"},{"introduced":"9.2.0"},{"last_affected":"9.2.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["9.2.0","v9.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68422.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}