← Terug naar overzicht

CVE-2026-77811 describes a stored Cross-Site Scripting (XSS) vulnerability in the dashboards-observability plugin for OpenSearch Dashboards. The flaw stems from improper input validation, allowing a remote authenticated user with write permissions to saved objects to upload malicious assets containing arbitrary web content. This enables the attacker to execute arbitrary JavaScript in the browser sessions of other users viewing the affected content. The attack requires authentication and write access to OpenSearch Dashboards saved objects, making it a privilege-dependent but high-impact issue. Successful exploitation could lead to session hijacking, credential theft, or further lateral movement within the platform. AWS has issued a security bulletin and patches are available in OpenSearch releases 2.19.6 and 3.4.0. Organizations using affected versions of OpenSearch Dashboards should upgrade immediately to mitigate the risk.

Affected products

  • OpenSearch Dashboards
  • dashboards-observability plugin

Related CVE's

  • CVE-2026-77811

Categories

  • Enterprise Applications
  • Identity & Access
  • Web Technologies