Opensearch Dashboards Opensearch Dashboards

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Opensearch Dashboards.

By the Year

In 2026 there have been 2 vulnerabilities in Opensearch Dashboards with an average score of 8.2 out of ten.

Year Vulnerabilities Average Score
2026 2 8.15

It may take a day or so for new Opensearch Dashboards vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Opensearch Dashboards Security Vulnerabilities

OpenSearch Dashboards 3.8 TVBZ RCE via JSON (Prototype Pollution)
CVE-2026-18420 8.8 - High - August 20, 2026

Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code execution.  To remediate this issue, users should upgrade to OpenSearch Dashboards 3.8 or later.

Prototype Pollution

OpenSearch Dashboards Capabilities Route Unbounded Payload DOS
CVE-2026-75897 7.5 - High - August 18, 2026

Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not bounded - might allow remote attackers to cause a denial of service via a crafted HTTP request.

Improper Validation of Specified Quantity in Input

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Opensearch Dashboards or by Opensearch? Click the Watch button to subscribe.

Opensearch
Vendor

subscribe