CVE-2025-68422 Overview
CVE-2025-68422 is an improper authorization vulnerability [CWE-863] in Elastic Kibana. An authenticated user can bypass intended permission restrictions by sending a crafted HTTP request. The flaw allows an attacker who lacks the live queries - read permission to retrieve the list of live queries.
The vulnerability affects the Osquery integration authorization logic in Kibana. Exploitation requires network access and valid low-privilege credentials but no user interaction. Elastic addressed the issue in Kibana 8.19.7, 9.1.7, and 9.2.1 through security advisory ESA-2025-39.
Critical Impact
Authenticated users without the live queries - read permission can enumerate live query data, exposing information about ongoing Osquery investigations and potentially aiding reconnaissance against defender activity.
Affected Products
- Elastic Kibana versions prior to 8.19.7
- Elastic Kibana versions prior to 9.1.7
- Elastic Kibana 9.2.0
Discovery Timeline
- 2025-12-18 - CVE CVE-2025-68422 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-68422
Vulnerability Analysis
The vulnerability resides in Kibana's authorization checks for the Osquery live queries API. Kibana enforces role-based access control through Elasticsearch security features and per-feature Kibana privileges. The live queries - read privilege gates access to endpoints that return live query metadata and results.
The affected endpoint fails to consistently evaluate the required privilege before returning data. An authenticated user without live queries - read can issue a crafted HTTP request to enumerate live queries. This exposes information about which hosts are being queried, what queries are running, and results returned by Osquery agents.
The disclosure impact is limited to confidentiality of live query information. Integrity and availability are not affected, and the flaw does not permit issuing new queries or modifying existing ones.
Root Cause
The root cause is missing or incomplete authorization enforcement in the request handler for the live queries listing endpoint. The handler does not verify that the caller holds the live queries - read Kibana privilege before returning records. This aligns with CWE-863 Incorrect Authorization, where an access check is performed but produces an incorrect result.
Attack Vector
An attacker requires network reachability to Kibana and valid authenticated credentials with any Kibana access. The attacker sends a crafted HTTP request to the affected Osquery API path. Kibana returns live query information despite the caller lacking the live queries - read permission. No user interaction is required. See the Elastic Kibana Security Update ESA-2025-39 for vendor details.
Detection Methods for CVE-2025-68422
Indicators of Compromise
- Authenticated HTTP requests to Kibana Osquery API endpoints from user accounts that are not assigned the live queries - read privilege.
- Unexpected successful 200 OK responses to live query listing endpoints from low-privileged service or analyst accounts.
- Anomalous enumeration patterns against /api/osquery/live_queries originating from non-SOC user sessions.
Detection Strategies
- Correlate Kibana audit logs with the assigned role of the requesting user to identify calls that should have been denied by the live queries - read privilege.
- Baseline normal Osquery API consumers and alert on new principals querying live query endpoints.
- Alert on high-volume enumeration of Osquery live query resources by a single session or API key.
Monitoring Recommendations
- Enable Kibana audit logging and forward events to a centralized SIEM for role-versus-action analysis.
- Monitor Elasticsearch security audit events for API key and token usage against Kibana Osquery routes.
- Track Kibana version telemetry to confirm all instances are running 8.19.7, 9.1.7, 9.2.1, or later.
How to Mitigate CVE-2025-68422
Immediate Actions Required
- Upgrade Kibana to version 8.19.7, 9.1.7, or 9.2.1 as specified in ESA-2025-39.
- Inventory all Kibana deployments and identify instances running 8.19.x prior to 8.19.7, 9.1.x prior to 9.1.7, and 9.2.0.
- Review recent Kibana audit logs for unauthorized access to Osquery live query endpoints by low-privilege accounts.
- Rotate credentials and API keys for any account that shows anomalous Osquery API access.
Patch Information
Elastic released fixes in Kibana 8.19.7, 9.1.7, and 9.2.1. Details are published in the Elastic Kibana Security Update ESA-2025-39. Administrators should follow standard Elastic upgrade procedures and verify version numbers after deployment.
Workarounds
- Restrict Kibana authentication to trusted users only and minimize the number of accounts with any Kibana access until patching is complete.
- Limit network exposure of Kibana to management networks using firewall rules or reverse proxy allow-lists.
- Disable or restrict the Osquery integration in Kibana if it is not required in the environment.
# Verify Kibana version after upgrade
curl -s -u <user>:<password> \
https://<kibana-host>:5601/api/status | \
jq '.version.number'
# Expected output: 8.19.7, 9.1.7, 9.2.1, or later
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
