Monday, September 7, 2026

Kibana CrowdStrike Connector Flaw Exposes Sensitive Credentials

A security issue in the Kibana CrowdStrike Connector allows attackers to access stored CrowdStrike credentials.

The flaw affects multiple versions of Kibana and can expose credentials across spaces within the same deployment. Elastic has released updates to resolve this issue and urges users to upgrade immediately.

Vulnerability Details

The flaw, tracked as CVE-2025-37728, arises from insufficient protection of credentials in the CrowdStrike Connector.

When a connector is created in one workspace or space within Kibana, the credentials used to access the CrowdStrike API are cached.

CVE IDAffected VersionsImpactCVSS 3.1 Score
CVE-2025-377287.x: ≤ 7.17.29
8.x: 8.14.0 to 8.18.7
8.19.x: 8.19.0 to 8.19.4
9.0.x: 9.0.0 to 9.0.7
9.1.x: 9.1.0 to 9.1.4
Partial credential leak5.4

A malicious user with access to another space can exploit this caching mechanism to retrieve credentials that belong to a different space.

The issue impacts any Kibana instance using the CrowdStrike Connector and can lead to unauthorized disclosure of credentials.

Affected Versions and Impact

The vulnerability affects all unsupported and supported versions of Kibana that include the CrowdStrike Connector prior to the patched releases.

While no direct data modification or deletion is possible through this flaw, leaked credentials can enable attackers to query CrowdStrike APIs, gather threat data, and potentially manipulate threat hunting workflows.

The risk is classified as Medium with a CVSSv3.1 score of 5.4, indicating that successful exploitation requires limited privileges and some user interaction but can result in partial confidentiality loss.

Any Kibana instance configured with the CrowdStrike Connector and running an impacted version is vulnerable. This includes set-ups in which users manage multiple spaces for organizing dashboards, alerts, and connectors.

Elastic has fixed the flaw in the following patched versions: 8.18.8, 8.19.5, 9.0.8, and 9.1.5. Users running affected versions should upgrade to one of these releases without delay.

No workaround or temporary mitigation is available, so upgrading is the only effective measure.

After upgrading, administrators should review connector configurations to ensure they are functioning correctly and rotate any credentials that may have been exposed.

Check your Kibana version and plan an upgrade to one of the fixed releases. Engage with your security team to verify connector health and consider rotating CrowdStrike API keys.

Finally, monitor Elastic’s security announcements channel for any additional guidance or updates.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

DPRK-Linked Hackers Backdoor HAProxy Servers to Spy on South Korean Organizations

A previously undocumented Linux espionage toolkit linked with medium...

Magento and Adobe Commerce StyleSmuggler 0-Day RCE Actively Exploited in Attacks

Security researchers have discovered an actively exploited, unauthenticated remote...

Fake Minecraft Mod Drops Myth Stealer RAT to Steal Passwords and Remotely Control PCs

A trojanized Minecraft optimization mod posing as a companion...

Hackers Can Use PEEP Chrome Extension to Steal Credentials and Execute Shell Commands

A newly identified Chromium-based post-exploitation toolkit named PEEP can...

Hackers Actively Exploiting MikroTik RouterOS MikroTrick Flaws to Take Full Control of Routers

Threat actors are actively exploiting critical vulnerabilities in MikroTik...

CrowdStrike Launches SafeMind Agentic AI Cybersecurity System Built With NVIDIA Nemotron

CrowdStrike has launched SafeMind, an AI-driven cybersecurity system developed...

Related Articles

Recent News