2026-085-AWSHigh

CVE-2026-18420 - Remote Code Execution via Prototype Pollution in OpenSearch Dashboards TSVB Plugin

Published
August 20, 2026
Last Modified

🔗 CVE IDs covered (1)

📋 Description

Bulletin ID: 2026-085-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/20/2026 13:30 PM PDT Description: Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards before 3.8 allows a remote authenticated user with standard data access permissions to execute arbitrary code on the server by sending a crafted JSON payload to the metrics visualization API endpoint. To mitigate this issue, users should upgrade to OpenSearch Dashboards 3.8 or later. Impacted products and versions: - OpenSearch-Dashboards (open-source, self-managed): >=3.0.0, - OpenSearch-Dashboards (AWS Managed): >=3.0.0,
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

🔗 References (1)