Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Kibana CrowdStrike Connector Flaw Exposes Sensitive Credentials

A security flaw in the Kibana CrowdStrike Connector allows unauthorized access to stored CrowdStrike credentials. This vulnerability impacts various Kibana versions and can expose credentials across different spaces within the same deployment. Elastic…

A security flaw in the Kibana CrowdStrike Connector allows unauthorized access to stored CrowdStrike credentials. This vulnerability impacts various Kibana versions and can expose credentials across different spaces within the same deployment. Elastic has released updates to address this issue and recommends immediate upgrades.

The vulnerability, identified as CVE-2025-37728, results from inadequate protection of credentials in the CrowdStrike Connector. Credentials used to access the CrowdStrike API are cached when a connector is created in one workspace, making them accessible across other spaces.

CVE ID Affected Versions Impact CVSS 3.1 Score

CVE-2025-37728

7.x: ≤ 7.17.29

9.1.x: 9.1.0 to 9.1.4

A security flaw in the Kibana CrowdStrike Connector allows unauthorized access to stored CrowdStrike credentials.
Jessica Grant · Thehackingpost

Partial credential leak 5.4

A malicious user with access to another space can exploit this caching mechanism to retrieve credentials from a different space. This issue affects any Kibana instance using the CrowdStrike Connector and can lead to unauthorized disclosure of credentials.

The vulnerability affects both unsupported and supported Kibana versions with the CrowdStrike Connector before the patched releases. While it does not allow direct data modification or deletion, leaked credentials could enable attackers to query CrowdStrike APIs and manipulate threat hunting workflows.

The risk is considered Medium, with a CVSSv3.1 score of 5.4, indicating that successful exploitation requires limited privileges and some user interaction but can result in partial confidentiality loss.

Advertisement

Any Kibana instance configured with the CrowdStrike Connector and running an impacted version is vulnerable. This includes setups where users manage multiple spaces for organizing dashboards, alerts, and connectors.

Elastic has resolved the flaw in the following patched versions: 8.18.8, 8.19.5, 9.0.8, and 9.1.5. Users of affected versions should upgrade to one of these releases without delay.

No workaround or temporary mitigation is available; upgrading is the only effective solution. After upgrading, administrators should review connector configurations to ensure they are functioning correctly and rotate any potentially exposed credentials.

Check your Kibana version and plan an upgrade to one of the fixed releases. Consult with your security team to verify connector health and consider rotating CrowdStrike API keys. Monitor Elastic’s security announcements channel for any additional guidance or updates.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories