Known Vulnerabilities for Opensearch by Amazon
Listed below are 10 of the newest known vulnerabilities associated with "Opensearch" by "Amazon".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-77811 json | Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user ... | Not Provided | 2026-08-21 | 2026-08-21 |
| CVE-2026-76211 json | phpMyFAQ before 4.1.7 fails to properly enforce CONFIGURATION_EDIT permission on admin API read endpoints for LDAP, Elasticse... | Not Provided | 2026-08-19 | 2026-08-20 |
| CVE-2026-75897 json | Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-63178 json | Onyx is an open-source AI platform. Prior to 4.3.0, Onyx Enterprise Edition's PATCH /manage/admin/user-group/{user_group_id} ... | Not Provided | 2026-08-17 | 2026-08-18 |
| CVE-2026-47835 json | In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, Op... | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-47026 json | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards). Supp... | Not Provided | 2026-07-21 | 2026-08-01 |
| CVE-2026-19671 json | Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompressed-by... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-19311 json | Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote use... | Not Provided | 2026-08-12 | 2026-08-13 |
| CVE-2026-18952 json | Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an au... | Not Provided | 2026-08-12 | 2026-08-21 |
| CVE-2026-18428 json | A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated... | Not Provided | 2026-08-13 | 2026-08-13 |