Description
Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function property nested inside an array to bypass validation.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 08 Sep 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function property nested inside an array to bypass validation. | |
| Title | Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards | |
| First Time appeared |
Aws
Aws amazon Opensearch Service Opensearch Opensearch opensearch Dashboards |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:aws:amazon_opensearch_service:*:*:*:*:*:*:*:* cpe:2.3:a:opensearch:opensearch_dashboards:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Aws
Aws amazon Opensearch Service Opensearch Opensearch opensearch Dashboards |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-09-08T19:41:25.224Z
Reserved: 2026-09-02T16:47:56.353Z
Link: CVE-2026-84942
No data.
Status : Received
Published: 2026-09-08T20:18:51.307
Modified: 2026-09-08T20:18:51.307
Link: CVE-2026-84942
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')