CVE-2026-77811: Aws Amazon Opensearch Service
High severity, CVSS 8.7. EPSS: 0.5% chance of exploitation in the next 30 days.
Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user with write permissions to OpenSearch Dashboards saved objects to execute arbitrary JavaScript in the context of other users' browser sessions by uploading a saved asset with arbitrary web content.
Affected products
- Aws Amazon Opensearch Service
- Opensearch Opensearch Dashboards Dashboards-Observability Plugin: before 3.4 (fixed in 3.4); before 2.19.6 (fixed in 2.19.6)
Published 2026-08-21. Last modified 2026-08-27.