CVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards

Opensearch Dashboards ยท 2026-09-09

Actions

Rate this issue

Technical Details

Affected Versions before 3.4, before 2.19.6
Regions all
CVE IDs CVE-2026-77811
Migration Required Yes
Cost Impact Neutral
IaC Impact High

What This Means

For DevOps Teams

Update OpenSearch Dashboards to versions 3.4 or 2.19.6 to address the stored cross-site scripting vulnerability (CVE-2026-77811) and ensure all domains are running the latest service software version to maintain security compliance.

For Platform Teams

Deploy the latest versions of OpenSearch Dashboards (3.4 and 2.19.6) to incorporate critical security fixes and maintain the integrity and security of the observability platform.

For Executives

Implement immediate updates to all OpenSearch Dashboards instances to mitigate the risk of stored cross-site scripting attacks, ensuring data integrity and user security across all deployments.

Source

View original AWS announcement โ†’

Related Opensearch Dashboards Updates

Weekly AWS Digest in Your Inbox

No spam, no headlines. Just a weekly summary of the 3โ€“7 AWS changes that matter for DevOps and Platform teams.

๐Ÿ“ง Exactly 1 email per week โ€ข Every Tuesday โ€ข Unsubscribe anytime

Today: AWS only. Coming next: Azure and other major clouds.