bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Thursday, August 20, 2026

OpenSearch Dashboards TSVB Plugin RCE Vulnerability – Upgrade Required

OpenSearch Dashboards versions 3.0.0 through 3.7.x have a nasty remote code execution flaw in the TSVB plugin. An authenticated attacker can craft a malicious JSON payload to execute arbitrary code on your server. You need to upgrade to version 3.8 or later immediately—this affects both self-managed and AWS-managed deployments.

source: [aws/security-bulletin]