Skip to main content

CVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards

Bulletin ID: 2026-088-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 08/21/2026 13:00 PM PDT

Description:

Amazon OpenSearch Service is a managed service that makes it easy to deploy, operate, and scale OpenSearch clusters. We identified CVE-2026-77811, a stored cross-site scripting issue in the dashboards-observability plugin in OpenSearch Dashboards. Improper input validation in the integrations static file endpoint allows a remote authenticated actor with write permissions to OpenSearch Dashboards saved objects to upload a custom integration containing arbitrary JavaScript. When another user accesses the static file endpoint directly, the script executes in their browser session and can perform actions on their behalf, including making API calls to OpenSearch with their privileges.

Affected products & versions:

OpenSearch Dashboards dashboards-observability plugin (open-source, self-managed):

  • Affected: versions before 3.4 and versions before 2.19.6
  • Fixed: versions 3.4 and 2.19.6

Amazon OpenSearch Service (AWS Managed):

  • Affected: versions before 3.3
  • Fixed: fixed in all affected versions (via service software update)

Resolution:

This issue has been addressed in All Amazon OpenSearch Service (managed) versions and OpenSearch (open source) versions 3.4 and 2.19.6. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

For OpenSearch (open-source), this issue has been addressed in OpenSearch Dashboards dashboards-observability plugin versions 3.4 and 2.19.6. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

For Amazon OpenSearch Service (managed), this issue has been addressed in all affected versions. We recommend that customers update their domains to the latest service software version as soon as possible. No engine version upgrade is required. You can apply the update from the console by selecting your domain, choosing Actions, Service Software Version, then clicking Update. Domains with automatic software updates enabled receive this update during their next off-peak window with no action required. For full details, see Service software updates in Amazon OpenSearch Service.

Workarounds:

Restrict write access for Dashboards saved objects to trusted users only. Avoid directly accessing assets from the integrations static file API in a browser or outside of the normal web UI.

References:


Please email aws-security@amazon.com with any security questions or concerns.