CVE-2026-75897

Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not bounded - might allow remote attackers to cause a denial of service via a crafted HTTP request.

  • Published Aug 18, 2026
  • CVSS 8.7 high
  • 0.7% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-75897 at the National Vulnerability Database