HomeSecurityVulnerability in Kibana Crowdstrike Connector exposes protected credentials

Vulnerability in Kibana Crowdstrike Connector exposes protected credentials

Elastic has issued a security advisory describing a medium severity vulnerability in the Kibana Crowdstrike Connector , which could allow the disclosure of sensitive credentials .

See also: CrowdStrike to lay off 500 employees

Crowdstrike Connector

The vulnerability, tracked as CVE-2025-37728, affects multiple versions of Kibana and could allow a malicious user to access stored CrowdStrike credentials from other users within the same environment. The vulnerability highlights the security risks associated with interconnected platforms and the importance of timely updates.

The vulnerability, labeled “Inadequately Protected Credentials in Crowdstrike Connector,” has a CVSSv3.1 rating of 5.4, making it a medium severity issue. According to Elastic’s security advisory, a malicious user with access to a location in a Kibana installation could create and execute a new CrowdStrike Connector. This action would allow them to access stored credentials from an existing CrowdStrike Connector running in a different location.

The vulnerability essentially allows unauthorized cross-workspace access to sensitive API credentials used to communicate between Kibana and the CrowdStrike Console Management. Successful exploitation could lead to credential leakage, potentially allowing an attacker to interact with the CrowdStrike platform with the privileges of the compromised account.

See also: Phishing email impersonates CrowdStrike and targets developers

Vulnerability in Kibana Crowdstrike Connector exposes protected credentials

Any Kibana installation using CrowdStrike Connector within these versions is considered vulnerable. Elastic has addressed the issue in versions 8.18.8, 8.19.5, 9.0.8 , and 9.1.5. The company strongly recommends that users upgrade to one of these patched versions to resolve the security gap. It is noted that Elastic has stated that there are no workarounds for users who cannot upgrade immediately, making the update the only viable solution.

The Kibana CrowdStrike Connector is designed to facilitate seamless data integration between the CrowdStrike Falcon platform and Elastic, enabling automated incident correlation and telemetry ingestion. The credentials leaked by this vulnerability are used to authenticate with the CrowdStrike REST API, making their protection critical to maintaining security on both platforms.

See also: Shai-Hulud supply chain attack: Over 180 NPM packages affected

Vulnerability in Kibana Crowdstrike Connector exposes protected credentials

The advisory (ESA-2025-19) was part of a larger security update from Elastic that addressed several other vulnerabilities in Kibana and Elasticsearch. Since there is no workaround, administrators of affected Kibana installations are urged to prioritize the update to prevent potential credential theft and subsequent misuse. Elastic emphasizes the importance of timely updates and configuration reviews to reduce exposure to such threats.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS