MEDIUM 6.3 NVD
CVE-2026-84942
Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permi
Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function property nested inside an array to bypass validation.
References
- https://aws.amazon.com/security/security-bulletins/2026-102-aws/
- https://github.com/opensearch-project/OpenSearch-Dashboards/releases/tag/2.19.5
- https://github.com/opensearch-project/OpenSearch-Dashboards/releases/tag/3.6.0
This medium severity vulnerability with a CVSS score of 6.3 was published on 2026-09-08 via NVD.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.