CVE-2026-84942 - Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards

Opensearch Dashboards ยท 2026-09-09

Actions

Rate this issue

Technical Details

Affected Versions v2.0.0, v2.1.0, v2.2.0, v2.3.0, v2.4.0, v2.5.0, v2.6.0, v2.7.0, v2.8.0, v2.9.0, v2.10.0, v2.11.0, v2.12.0, v2.13.0, v2.14.0, v2.15.0, v2.16.0, v2.17.0, v2.18.0, v2.19.0, v3.0.0, v3.1.0, v3.2.0, v3.3.0, v3.4.0, v3.5.0
Regions all
CVE IDs CVE-2026-84942
Migration Required Yes
Cost Impact Neutral
IaC Impact High

What This Means

For DevOps Teams

Update OpenSearch Dashboards to versions 2.19.5 or 3.6.0 to patch the stored XSS vulnerability and restrict write access to visualization APIs to trusted users until the update is applied.

For Platform Teams

Deploy the latest versions of OpenSearch Dashboards (2.19.5 or 3.6.0) to incorporate enhanced Vega expression validation and ensure the security of visualization functionalities.

For Executives

Implement immediate updates to OpenSearch Dashboards to address the stored cross-site scripting vulnerability (CVE-2026-84942) and ensure data security across all user sessions.

Source

View original AWS announcement โ†’

Related Opensearch Dashboards Updates

Weekly AWS Digest in Your Inbox

No spam, no headlines. Just a weekly summary of the 3โ€“7 AWS changes that matter for DevOps and Platform teams.

๐Ÿ“ง Exactly 1 email per week โ€ข Every Tuesday โ€ข Unsubscribe anytime

Today: AWS only. Coming next: Azure and other major clouds.