References https://forum.opensearch.org/t/what-are-the-correct-default-username-and-password-for-opensearch-dashboards/8970 https://docs.escape.tech/documentation/reference/vulnerabilities/opensearch_dashboard_default_login/ https://opensearch.org/blog/replacing-default-admin-credentials/ https://github.com/opensearch-project/security/issues/4068 https://opster.com/guides/opensearch/opensearch-security/opensearch-default-username-and-password/ https://docs.opensearch.org/latest/security/getting-started/ https://juejin.cn/post/7330851925057470504 https://forum.opensearch.org/t/default-password-for-opensearch-dashboard-with-opensearch-cluster-deployed-using-aws-opensearch-service/16649
Related VulnerabilitiesPoCCVE-2026-44343: WGDashboard < 4.3.2 - Unauthenticated File ReadPoCCVE-2026-59177: ESPHome Device Builder <1.0.10 - Unauthenticated Dashboard AccessPoCCVE-2026-15733: WGDashboard <= 4.3.2 - Authenticated OS Command Injection /etc/passwd ReadPoCCVE-2026-53519: Nezha Dashboard < 2.0.13 - Path TraversalPoCtrino-unauth-cluster: Trino Cluster Overview - Unauthenticated Dashboard ExposureKubernetes Dashboard /api/v1/namespaces/kube-system/secrets/kubernetes-dashboard-certs 权限绕过漏洞(CVE-2018-18264)Nezha Dashboard /dashboard../data/config.yaml 目录遍历漏洞(CVE-2026-53519)PoClaravel-pulse-unauth: Laravel Pulse - Unauthenticated Dashboard AccessPoCpuppetdb-dashboard-unauth: PuppetDB Dashboard - Unauthenticated AccessKubeflow Dashboard /api/workgroup/env-info 未授权访问漏洞PoCapache-skywalking-dashboard: Apache SkyWalking - DashboardPoCCVE-2025-54597: Heimdall Application Dashboard < 2.7.3 - Reflected XSSPoCargo-workflows-unauth: Argo Workflows - Unauthenticated Dashboard