CVE-2026-75897 - Uncontrolled resource consumption in OpenSearch Dashboards capabilities route
Opensearch Service ยท 2026-09-09
Actions
Technical Details
| Affected Versions | 1.3.0 through 3.7.0, OpenSearch 1.3, 2.11, 2.13, 2.15, 2.17, 2.19, 3.1, 3.3, and 3.5 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-75897 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update your OpenSearch Dashboards to version 3.8.0 or later, and apply the latest service software updates for Amazon OpenSearch Service to address the security vulnerability CVE-2026-75897 and prevent denial of service attacks.
For Platform Teams
Deploy the patched service software updates for Amazon OpenSearch Service and upgrade OpenSearch Dashboards to version 3.8.0 or later to resolve the security issue and maintain system integrity.
For Executives
Implement the latest service software updates for Amazon OpenSearch Service to mitigate the security vulnerability identified in CVE-2026-75897, ensuring system stability and protecting against potential denial of service attacks.
Source
Related Opensearch Service Updates
- CVE-2026-18428 - OpenSearch SQL Plugin - Async Query Validation Bypass (2026-09-09)
- CVE-2026-83497 - OpenSearch SQL Plugin - Unrestricted Java Deserialization in Cursor Pagination (2026-09-09)
- CVE-2026-18952 - Missing Input Validation in OpenSearch Security Analytics Plugin (2026-09-09)
- CVE-2026-19311- Missing Authorization in OpenSearch Alerting Plugin (2026-09-09)
- Amazon OpenSearch Service adds new Cluster Insights for faster diagnosis of cluster status (2026-08-31)