Known Vulnerabilities for Opensearch by AWS
Listed below are 10 of the newest known vulnerabilities associated with "Opensearch" by "AWS".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-83497 json | Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remot... | Not Provided | 2026-08-31 | 2026-09-01 |
| CVE-2026-82880 json | YaCy Search Server through 1.941 contains an XML external entity injection vulnerability in SVG, FreeMind, and OpenSearch par... | Not Provided | 2026-08-31 | 2026-08-31 |
| CVE-2026-77811 json | Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user ... | Not Provided | 2026-08-21 | 2026-08-27 |
| CVE-2026-76211 json | phpMyFAQ before 4.1.7 fails to properly enforce CONFIGURATION_EDIT permission on admin API read endpoints for LDAP, Elasticse... | Not Provided | 2026-08-19 | 2026-08-20 |
| CVE-2026-75897 json | Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-63178 json | Onyx is an open-source AI platform. Prior to 4.3.0, Onyx Enterprise Edition's PATCH /manage/admin/user-group/{user_group_id} ... | Not Provided | 2026-08-17 | 2026-08-18 |
| CVE-2026-47835 json | In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, Op... | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-47026 json | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards). Supp... | Not Provided | 2026-07-21 | 2026-08-01 |
| CVE-2026-19671 json | Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompressed-by... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-19311 json | Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote use... | Not Provided | 2026-08-12 | 2026-08-13 |