# CVE-2025-25014

## Summary

- **CVE ID:** CVE-2025-25014
- **Severity:** CRITICAL
- **CVSS Score:** 9.1 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-1321
- **Published:** May 6, 2025
- **Last Modified:** Mar 12, 2026

## Description

A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.

## Affected Products

- Elastic — Kibana (8.3.0)
- Elastic — Kibana (8.18.0)
- Elastic — Kibana (9.0.0)

## References

- [CNA](https://discuss.elastic.co/t/kibana-8-17-6-8-18-1-or-9-0-1-security-update-esa-2025-07/377868)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 21.48%
- **EPSS Percentile:** 97.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._