bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: CVE-2026-77811

show all
Friday, August 21, 2026

OpenSearch Dashboards XSS Vulnerability Requires Immediate Patching

OpenSearch Dashboards has a stored XSS flaw (CVE-2026-77811) in the dashboards-observability plugin that lets authenticated users inject malicious scripts. If you're running self-managed versions before 3.4 or 2.19.6, update immediately—AWS managed users are already patched. An attacker with write access can execute JavaScript in other users' browsers and hijack their API calls.

source: [aws/security-bulletin]