CVE-2026-18420

Source
https://cve.org/CVERecord?id=CVE-2026-18420
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18420.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-18420
Aliases
  • GHSA-xmqx-xq2p-8jq2
Published
2026-08-20T20:40:40.709Z
Modified
2026-08-22T03:49:54.588734963Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
RCE via Prototype Pollution in OpenSearch Dashboards
Details

Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code execution. 

To remediate this issue, users should upgrade to OpenSearch Dashboards 3.8 or later.

Database specific
{
    "cwe_ids": [
        "CWE-1321"
    ],
    "cna_assigner": "AMZN",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18420.json"
}
References

Affected packages

Git / github.com/opensearch-project/opensearch-dashboards

Affected ranges

Type
GIT
Repo
https://github.com/opensearch-project/opensearch-dashboards
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "3.0.0"
        },
        {
            "fixed": "3.8.0"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18420.json"