CVE-2026-77811 - Stored Cross-... Note

CVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards

Amazon OpenSearch Service has released an important bulletin regarding a security vulnerability. The vulnerability, identified as CVE-2026-77811, is a stored cross-site scripting issue. It specifically affects the dashboards-observability plugin within OpenSearch Dashboards. This flaw arises from improper input validation in the integrations static file endpoint.A remote authenticated actor with write permissions to saved objects can exploit this by uploading a custom integration. This integration can contain arbitrary JavaScript code. When another user accesses the static file endpoint, the malicious script runs in their browser. This can lead to actions being performed as that user, including unauthorized API calls.For open-source, self-managed OpenSearch Dashboards, versions prior to 3.4 and 2.19.6 are affected. Versions 3.4 and 2.19.6 contain the fix. For Amazon OpenSearch Service, versions prior to 3.3 are affected. AWS has addressed this vulnerability in all affected managed versions through a service software update. Users are encouraged to consult the full article for comprehensive details.