OpenSearch Dashboards XSS Vulnerability Requires Immediate Patching
OpenSearch Dashboards has a stored XSS flaw (CVE-2026-77811) in the dashboards-observability plugin that lets authenticated users inject malicious scripts. If you're running self-managed versions before 3.4 or 2.19.6, update immediately—AWS managed users are already patched. An attacker with write access can execute JavaScript in other users' browsers and hijack their API calls.
source: [aws/security-bulletin]