CVE-2026-18420 - Remote Code Execution via Prototype Pollution in OpenSearch Dashboards TSVB Plugin
🔗 CVE IDs covered (1)
📋 Description
Bulletin ID: 2026-085-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/20/2026 13:30 PM PDT
Description:
Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards before 3.8 allows a remote authenticated user with standard data access permissions to execute arbitrary code on the server by sending a crafted JSON payload to the metrics visualization API endpoint. To mitigate this issue, users should upgrade to OpenSearch Dashboards 3.8 or later.
Impacted products and versions: - OpenSearch-Dashboards (open-source, self-managed): >=3.0.0, - OpenSearch-Dashboards (AWS Managed): >=3.0.0,
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.