CVE-2026-18420 - Remote Code Execution via Prototype Pollution in OpenSearch Dashboards TSVB Plugin
Opensearch Service ยท 2026-08-20
Actions
Technical Details
| Affected Versions | >= 3.0.0, < 3.8.0 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-18420 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Upgrade OpenSearch Dashboards to version 3.8.0 or later to address the prototype pollution vulnerability in the TSVB plugin and prevent potential remote code execution.
For Platform Teams
Integrate the latest security patches for OpenSearch Dashboards to ensure the platform remains secure and compliant with industry standards.
For Executives
Implement the security patch for OpenSearch Dashboards to mitigate the risk of remote code execution and protect sensitive data from potential breaches.
Source
Related Opensearch Service Updates
- CVE-2026-18428 - OpenSearch SQL Plugin - Async Query Validation Bypass (2026-08-20)
- CVE-2026-15746 - Credential disclosure in Strands Agents Tools elasticsearch_memory tool (2026-08-20)
- CVE-2026-18952 - Missing Input Validation in OpenSearch Security Analytics Plugin (2026-08-20)
- CVE-2026-19311- Missing Authorization in OpenSearch Alerting Plugin (2026-08-20)
- Amazon OpenSearch Ingestion is now available in GovCloud Regions (2026-08-19)