CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-75897

highCVSS 7.5covered by 2 sourcesfirst seen 2026-08-18
Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not bounded - might allow remote attackers to cause a denial of service via a crafted HTTP request.

CSIRTS triage

vendor: Amazonproduct: OpenSearch DashboardsDenial of serviceaffected: 1.3.0 through 3.7.0, 2.0 through 2.19.6, and inherited from Kibana 7.7.1 through 7.10.2
What
OpenSearch Dashboards contains improper input validation in the capabilities route handler allowing unbounded resource consumption.
Who is affected
OpenSearch Dashboards self-managed deployments and Amazon OpenSearch Service instances running versions 1.3.0 through 3.7.0 or Kibana 7.7.1 through 7.10.2.
Urgency
Important; denial of service vulnerability enabling remote attackers to consume server resources via crafted requests.
Action
Upgrade OpenSearch Dashboards to version 3.8.0 or later, or upgrade Kibana to 7.10.3 or later.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-75897

Get an email if CVE-2026-75897 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-75897

CVE.org record

Embed the live status

CVE-2026-75897 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-75897 status](https://www.csirts.com/badge/CVE-2026-75897)](https://www.csirts.com/cve/CVE-2026-75897)