Remote Code Execution via Prototype Pollution in OpenSearch Dashboards TSVB Plugin
UnratedCVE-2026-18420 · Published Aug 20, 2026 · updated Sep 9, 2026
Bulletin ID: 2026-085-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/20/2026 13:30 PM PDT Description: Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards before 3.8 allows a remote authenticated user with standard data access permissions to execute arbitrary code on the server by sending a crafted JSON payload to the metrics visualization API endpoint. To mitigate this issue, users should upgrade to OpenSearch Dashboards 3.8 or later. Impacted products and versions: - OpenSearch-Dashboards (open-source, self-managed): >=3.0.0, =3.0.0, <3.8.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Affected versions
Details and references
- Severity from
- no source yet
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 21 | Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards | Unrated | No fix yet |
| Aug 21 | Issue with Athena Federated Query Neptune Connector | Unrated | No fix yet |
| Aug 21 | Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236... | Unrated | No fix yet |
| Aug 20 | Issue with Athena Federated Query Clickhouse Connector | Unrated | No fix yet |
| Aug 18 | Issue with Amazon ion-java - Memory-amplification denial of service | Unrated | No fix yet |
| Aug 18 | Uncontrolled resource consumption in OpenSearch Dashboards capabilities route | Unrated | No fix yet |