#VU116635 Insufficiently protected credentials in Kibana - CVE-2025-37728
Published: October 6, 2025
Kibana
Elastic Stack
Description
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to insufficient protection of credentials in the Crowdstrike connector. A remote user can access cached credentials from an Elastic Crowdstrike connector in another space by creating and running a Crowdstrike connector in a space to which they have access.