Known Vulnerabilities for Aws Opensearch by Amazon
Listed below are 1 of the newest known vulnerabilities associated with "Aws Opensearch" by "Amazon".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-56699 json | Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowi... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-47835 json | In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, Op... | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-47026 json | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards). Supp... | Not Provided | 2026-07-21 | 2026-07-23 |
| CVE-2026-43826 json | The OpenSearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:passwor... | Not Provided | 2026-05-11 | 2026-05-11 |
| CVE-2026-7191 json | Improper use of the static-eval npm package in the open source solution qnabot-on-aws versions 7.2.4 and earlier may allow an... | Not Provided | 2026-04-27 | 2026-04-28 |
| CVE-2021-44833 json | The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file. | 9.8 - CRITICAL | 2021-12-12 | 2021-12-15 |