CVE-2019-7609
Kibana Arbitrary Code Execution
- Published
- Mar 25, 2019
- Updated
- Oct 21, 2025
- Assigning CNA
- elastic
- Evidence observed
- Jan 10, 2022
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
Sources
13- CVE-2019-7069-POCExploit
Python 3 exploit for Kibana < 6.6.1 RCE (CVE-2019-7609) via prototype pollution, with automatic version detection and optional reverse shell.
- cve-2019-7609Exploit
Kibana <6.6.0 RCE written in python3
Proof-of-concept exploit for Kibana Timelion prototype pollution vulnerability (CVE-2019-7609) enabling remote code execution, with Docker-based lab setup and debugging instructions.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.