# Kibana 8.12.1 Security Update (ESA-2024-21)

**URL:** <https://discuss.elastic.co/t/kibana-8-12-1-security-update-esa-2024-21/379064>\
**Category:** Security Announcements\
**Created:** [June 10, 2025, 4:48pm UTC](https://discuss.elastic.co/t/kibana-8-12-1-security-update-esa-2024-21/379064 "2025-06-10T16:48:27Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![rodrigo\_silva](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rodrigo_silva/32/120546_2.png) [@rodrigo\_silva](https://discuss.elastic.co/u/rodrigo_silva)\
**Post date:** [June 10, 2025, 4:48pm UTC](https://discuss.elastic.co/t/kibana-8-12-1-security-update-esa-2024-21/379064/1 "2025-06-10T16:48:27Z")

</div>

**Kibana Improper Authorization (ESA-2024-21)**

Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint.

**Affected Versions:**

Kibana versions before and including 8.12.0.

**Solutions and Mitigations:**

The issue is resolved in versions 8.12.1.

**For Users that Cannot Upgrade:**

Self-hosted:  
Users with a self-hosted deployment who cannot upgrade can disable the synthetics app OR put a block on synthetics indices.

1. Disable the synthetics by adding `xpack.uptime.enabled: false` to their `kibana.yml` file
2. Put an index block on the synthetics-\* indices to make them read-only [see](https://www.elastic.co/docs/reference/elasticsearch/index-settings/index-block)

Elastic Cloud:  
Users on an Elastic Cloud deployment who cannot upgrade can put a block on synthetics indices

1. Put an index block on the synthetics-\* indices to make them read-only [see](https://www.elastic.co/docs/reference/elasticsearch/index-settings/index-block)

**Severity** : High (7.6) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L/CR:M/IR:M/AR:M  
**CVE ID** : CVE-2024-43706
