CVE-2026-84942 - Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards
Cybersecurity Classified by Officially
CVE-2026-84942 - Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards
Bulletin ID: 2026-102-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/08/2026 12:30 PM PDT
A stored cross-site scripting (XSS) issue in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization.
- Affected:
v2.0.0, v2.1.0, v2.2.0, v2.3.0, v2.4.0, v2.5.0, v.2.6.0, v2.7.0, v2.8.0, v2.9.0, v2.10.0, v2.11.0, v2.12.0, v2.13.0, v2.14.0, v2.15.0, v2.16.0, v2.17.0, v2.18.0, v2.19.0, v3.0.0, v3.1.0, v3.2.0, v3.3.0, v3.4.0, v3.5.0
- Fixed:
v2.19.5 and v3.6.0
- Affected:
v2.3.0, v2.5.0, v2.7.0, v2.9.0, v2.11.0, v2.13.0, v2.15.0, v2.17.0, v2.19.0, v3.1.0, v3.3.0, v3.5.0
- Fixed:
v2.3.0, v2.5.0, v2.7.0, v2.9.0, v2.11.0, v2.13.0, v2.15.0, v2.17.0, v2.19.0 and v3.1.0, v3.3.0, v3.5.0
- Not affected
For OpenSearch (open-source), this issue has been addressed in OpenSearch Dashboards 2.19.5 and 3.6.0. We recommend upgrading to one of these versions or later, which includes additional hardening of Vega expression validation, and ensuring any forked or derivative code is patched to incorporate the new fixes.
This is an extract. The publication continues at the source.
Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-102-aws/
Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
This publication has changed since it was first published
2 versions recorded. The original is kept in full — nothing is overwritten.
- v2 imported change on current
- v1 as first published on
Provenance
- Organization
- Amazon Web Services — imported from official source
- Official source
- https://aws.amazon.com/security/security-bulletins/feed/ RSS
- Imported
- September 15, 2026 20:57
- Versions
- 2 recorded
- Identity
ee09ab7fd29f155e023ed25e0ceabdf8379daca2