Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function property nested inside an array to bypass validation. | |
| Title | Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards | |
| First Time appeared |
Aws
Aws amazon Opensearch Service Opensearch Opensearch opensearch Dashboards |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:aws:amazon_opensearch_service:*:*:*:*:*:*:*:* cpe:2.3:a:opensearch:opensearch_dashboards:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Aws
Aws amazon Opensearch Service Opensearch Opensearch opensearch Dashboards |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-09-08T19:41:25.224Z
Reserved: 2026-09-02T16:47:56.353Z
Link: CVE-2026-84942
No data.
Status : Received
Published: 2026-09-08T20:18:51.307
Modified: 2026-09-08T20:18:51.307
Link: CVE-2026-84942
No data.
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')