Description
Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function property nested inside an array to bypass validation.
Published: 2026-09-08
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting enabling arbitrary JavaScript execution in other users’ browsers
Action: Immediate Patch
AI Analysis

Impact

OpenSearch Dashboards contains an input validation flaw in the Vega expression function implementation. The checkForFunctionProperty routine fails to recurse into arrays of objects, so a function property can be nested inside an array and bypass validation. An authenticated user with dashboard write permissions can save a crafted Vega visualization that includes arbitrary JavaScript. When other users load the visualization, the script runs in their browser context, potentially compromising their session data and allowing further malicious actions. The vulnerability falls under CWE‑79, a stored cross‑site scripting flaw.

Affected Systems

This flaw affects AWS Amazon OpenSearch Service and OpenSearch Dashboards from versions prior to 2.19.5 and 3.6.0. Users running older releases should verify their current version and upgrade as appropriate.

Risk and Exploitability

The CVSS score of 6.3 indicates a moderate severity, and the EPSS score is unavailable. The vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated and have dashboard write permissions, but once authenticated they can embed malicious code that is persisted in the dashboard for future users to load. The exploit requires only the ability to create or edit a Vega visualization, a common capability for many dashboard users.

Generated by OpenCVE AI on September 9, 2026 at 14:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest OpenSearch Dashboards patch (2.19.5 or 3.6.0) or later, which fixes the function property validation.
  • Review and restrict dashboard write permissions: grant write access only to trusted administrators or required service accounts.
  • If a patch cannot be applied immediately, enforce manual input validation or content filtering on Vega expressions to block function properties before they are saved.

Generated by OpenCVE AI on September 9, 2026 at 14:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function property nested inside an array to bypass validation.
Title Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards
First Time appeared Aws
Aws amazon Opensearch Service
Opensearch
Opensearch opensearch Dashboards
Weaknesses CWE-79
CPEs cpe:2.3:a:aws:amazon_opensearch_service:*:*:*:*:*:*:*:*
cpe:2.3:a:opensearch:opensearch_dashboards:*:*:*:*:*:*:*:*
Vendors & Products Aws
Aws amazon Opensearch Service
Opensearch
Opensearch opensearch Dashboards
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N'}


Subscriptions

Aws Amazon Opensearch Service
Opensearch Opensearch Dashboards
cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-09-09T20:51:34.759Z

Reserved: 2026-09-02T16:47:56.353Z

Link: CVE-2026-84942

cve-icon Vulnrichment

Updated: 2026-09-09T20:46:23.723Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T20:18:51.307

Modified: 2026-09-09T21:17:05.473

Link: CVE-2026-84942

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T19:00:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')