Opensearch Dashboards
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Opensearch Dashboards.
By the Year
In 2026 there have been 2 vulnerabilities in Opensearch Dashboards with an average score of 8.2 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 2 | 8.15 |
It may take a day or so for new Opensearch Dashboards vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Opensearch Dashboards Security Vulnerabilities
OpenSearch Dashboards 3.8 TVBZ RCE via JSON (Prototype Pollution)
CVE-2026-18420
8.8 - High
- August 20, 2026
Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code execution. To remediate this issue, users should upgrade to OpenSearch Dashboards 3.8 or later.
Prototype Pollution
OpenSearch Dashboards Capabilities Route Unbounded Payload DOS
CVE-2026-75897
7.5 - High
- August 18, 2026
Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not bounded - might allow remote attackers to cause a denial of service via a crafted HTTP request.
Improper Validation of Specified Quantity in Input
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Opensearch Dashboards or by Opensearch? Click the Watch button to subscribe.