CVE-2026-18420 - Remote Code Execution via Prototype Pollution in OpenSearch Dashboards TSVB Plugin
Opensearch Dashboards ยท 2026-09-09
Actions
Technical Details
| Affected Versions | >= 3.0.0, < 3.8.0 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-18420 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update OpenSearch Dashboards to version 3.8.0 or later, and apply the latest service software update for AWS Managed OpenSearch Dashboards to address the CVE-2026-18420 vulnerability.
For Platform Teams
Deploy the updated OpenSearch Dashboards version 3.8.0 or later to ensure the platform is secure from the prototype pollution vulnerability in the TSVB plugin.
For Executives
Implement immediate security measures to upgrade OpenSearch Dashboards to version 3.8.0 or later to mitigate the risk of remote code execution via prototype pollution in the TSVB plugin.
Source
Related Opensearch Dashboards Updates
- CVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards (2026-09-09)
- CVE-2026-84942 - Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards (2026-09-09)
- CVE-2026-84942 - Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards (2026-09-08)
- Amazon RDS now supports the latest CU and GDR updates for Microsoft SQL Server (2026-09-08)
- Amazon RDS for MariaDB now supports community MariaDB minor versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, and 12.3.3 (2026-09-08)