Prototype Pollution in Time Series Visual Builder Plugin for OpenSearch Dashboards
CVE-2026-18420
8.7HIGH
Key Information:
- Vendor
Aws
- Vendor
- CVE Published:
- 20 August 2026
What is CVE-2026-18420?
A vulnerability in the Time Series Visual Builder (TSVB) plugin of OpenSearch Dashboards allows authenticated remote users to exploit improper input validation. This oversight enables the execution of arbitrary code on the server through a specially crafted JSON payload sent to the metrics visualization API endpoint. The flaw is categorized as a form of prototype pollution, which can lead to significant security risks, including unauthorized access and manipulation of the server's operations. Users are advised to upgrade to OpenSearch Dashboards version 3.8 or later to mitigate this vulnerability.
Affected Version(s)
Amazon OpenSearch Service 3.0.0 < 3.8.0
OpenSearch Dashboards 3.0.0 < 3.8.0
