Prototype Pollution in Time Series Visual Builder Plugin for OpenSearch Dashboards
CVE-2026-18420

8.7HIGH

Key Information:

Vendor

Aws

Vendor
CVE Published:
20 August 2026

What is CVE-2026-18420?

A vulnerability in the Time Series Visual Builder (TSVB) plugin of OpenSearch Dashboards allows authenticated remote users to exploit improper input validation. This oversight enables the execution of arbitrary code on the server through a specially crafted JSON payload sent to the metrics visualization API endpoint. The flaw is categorized as a form of prototype pollution, which can lead to significant security risks, including unauthorized access and manipulation of the server's operations. Users are advised to upgrade to OpenSearch Dashboards version 3.8 or later to mitigate this vulnerability.

Affected Version(s)

Amazon OpenSearch Service 3.0.0 < 3.8.0

OpenSearch Dashboards 3.0.0 < 3.8.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.