bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Friday, August 21, 2026

OpenSearch Dashboards XSS Vulnerability Requires Immediate Patching

OpenSearch Dashboards has a stored XSS flaw (CVE-2026-77811) in the dashboards-observability plugin that lets authenticated users inject malicious scripts. If you're running self-managed versions before 3.4 or 2.19.6, update immediately—AWS managed users are already patched. An attacker with write access can execute JavaScript in other users' browsers and hijack their API calls.

source: [aws/security-bulletin]