Improper Input Validation in OpenSearch Dashboards by OpenSearch
CVE-2026-84942

6.3MEDIUM

Key Information:

Vendor

Aws

Vendor
CVE Published:
8 September 2026

What is CVE-2026-84942?

A vulnerability exists in OpenSearch Dashboards due to improper input validation associated with the Vega expression function implementation. This flaw enables an attacker with dashboard write permissions to execute arbitrary JavaScript in the browser sessions of other users. Specifically, the validation process does not effectively recurse into arrays of objects, allowing attackers to insert function properties into a crafted Vega visualization that can bypass validation checks. As a result, this ability leads to potential remote code execution risks within user sessions.

Affected Version(s)

OpenSearch Dashboards v2.0.0

Amazon OpenSearch Service v2.3.0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.