CVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards
Opensearch Dashboards ยท 2026-09-09
Actions
Technical Details
| Affected Versions | before 3.4, before 2.19.6 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-77811 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update OpenSearch Dashboards to versions 3.4 or 2.19.6 to address the stored cross-site scripting vulnerability (CVE-2026-77811) and ensure all domains are running the latest service software version to maintain security compliance.
For Platform Teams
Deploy the latest versions of OpenSearch Dashboards (3.4 and 2.19.6) to incorporate critical security fixes and maintain the integrity and security of the observability platform.
For Executives
Implement immediate updates to all OpenSearch Dashboards instances to mitigate the risk of stored cross-site scripting attacks, ensuring data integrity and user security across all deployments.
Source
Related Opensearch Dashboards Updates
- CVE-2026-18420 - Remote Code Execution via Prototype Pollution in OpenSearch Dashboards TSVB Plugin (2026-09-09)
- CVE-2026-84942 - Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards (2026-09-09)
- CVE-2026-84942 - Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards (2026-09-08)
- Amazon RDS now supports the latest CU and GDR updates for Microsoft SQL Server (2026-09-08)
- Amazon RDS for MariaDB now supports community MariaDB minor versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, and 12.3.3 (2026-09-08)