Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code execution.
To remediate this issue, users should upgrade to OpenSearch Dashboards 3.8 or later.
Metrics
Affected Vendors & Products
References
History
Thu, 20 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code execution. To remediate this issue, users should upgrade to OpenSearch Dashboards 3.8 or later. | |
| Title | RCE via Prototype Pollution in OpenSearch Dashboards | |
| First Time appeared |
Aws
Aws amazon Opensearch Service Opensearch Opensearch opensearch Dashboards |
|
| Weaknesses | CWE-1321 | |
| CPEs | cpe:2.3:a:aws:amazon_opensearch_service:*:*:*:*:*:*:*:* cpe:2.3:a:opensearch:opensearch_dashboards:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Aws
Aws amazon Opensearch Service Opensearch Opensearch opensearch Dashboards |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-08-20T20:40:40.709Z
Reserved: 2026-07-30T18:11:08.464Z
Link: CVE-2026-18420
No data.
Status : Received
Published: 2026-08-20T21:17:06.137
Modified: 2026-08-20T21:17:06.137
Link: CVE-2026-18420
No data.
OpenCVE Enrichment
Updated: 2026-08-21T01:30:05Z