


Perceptive Security
SOC/SIEM Consultancy

Kibana 8.19.9, 9.1.9, and 9.2.3 Security Update (ESA-2025-34)
Published:
18 December 2025 at 21:24:54
Alert date:
18 December 2025 at 22:04:21
Source:
discuss.elastic.co
Kibana versions 7.x through 9.2.2 contain a Cross-site Scripting (XSS) vulnerability (CVE-2025-68385) that bypasses previous Vega XSS mitigations. The vulnerability allows authenticated users to embed malicious scripts in web content served to browsers. Affected versions include all 7.x versions, 8.0.0-8.19.8, 9.0.0-9.1.8, and 9.2.0-9.2.2. The issue is resolved in versions 8.19.9, 9.1.9, and 9.2.3. The vulnerability has a CVSSv3.1 score of 7.2 (High severity) with network attack vector and no required user interaction.
Technical details
Mitigation steps:
Affected products:
Kibana
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
