Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function property nested inside an array to bypass validation.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 08 Sep 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function property nested inside an array to bypass validation. | |
| Title | Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards | |
| First Time appeared |
Aws
Aws amazon Opensearch Service Opensearch Opensearch opensearch Dashboards |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:aws:amazon_opensearch_service:*:*:*:*:*:*:*:* cpe:2.3:a:opensearch:opensearch_dashboards:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Aws
Aws amazon Opensearch Service Opensearch Opensearch opensearch Dashboards |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-09-08T19:41:25.224Z
Reserved: 2026-09-02T16:47:56.353Z
Link: CVE-2026-84942
No data.
Status : Received
Published: 2026-09-08T20:18:51.307
Modified: 2026-09-08T20:18:51.307
Link: CVE-2026-84942
No data.
OpenCVE Enrichment
No data.
Weaknesses