CVE-2026-84942 - Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards

Imported from official source

Security notice

Cybersecurity Classified by Officially

CVE-2026-84942 - Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards

Bulletin ID: 2026-102-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/08/2026 12:30 PM PDT

A stored cross-site scripting (XSS) issue in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization.

  • OpenSearch Dashboards (open-source, self-managed)
    - Affected:
    v2.0.0, v2.1.0, v2.2.0, v2.3.0, v2.4.0, v2.5.0, v.2.6.0, v2.7.0, v2.8.0, v2.9.0, v2.10.0, v2.11.0, v2.12.0, v2.13.0, v2.14.0, v2.15.0, v2.16.0, v2.17.0, v2.18.0, v2.19.0, v3.0.0, v3.1.0, v3.2.0, v3.3.0, v3.4.0, v3.5.0
    - Fixed:
    v2.19.5 and v3.6.0

  • Amazon OpenSearch Service (AWS Managed)
    - 
    Affected:
    v2.3.0, v2.5.0, v2.7.0, v2.9.0, v2.11.0, v2.13.0, v2.15.0, v2.17.0, v2.19.0, v3.1.0, v3.3.0, v3.5.0
    - Fixed:
    v2.3.0, v2.5.0, v2.7.0, v2.9.0, v2.11.0, v2.13.0, v2.15.0, v2.17.0, v2.19.0 and v3.1.0, v3.3.0, v3.5.0

  • Amazon OpenSearch Serverless
    - Not affected
  • For OpenSearch (open-source), this issue has been addressed in OpenSearch Dashboards 2.19.5 and 3.6.0. We recommend upgrading to one of these versions or later, which includes additional hardening of Vega expression validation, and ensuring any forked or derivative code is patched to incorporate the new fixes.

    This is an extract. The publication continues at the source.

    Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-102-aws/

    Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    This publication has changed since it was first published

    2 versions recorded. The original is kept in full — nothing is overwritten.

    1. v2 imported change on current
    2. v1 as first published on

    Provenance

    Organization
    Amazon Web Services — imported from official source
    Official source
    https://aws.amazon.com/security/security-bulletins/feed/ RSS
    Imported
    September 15, 2026 20:57
    Versions
    2 recorded
    Identity
    ee09ab7fd29f155e023ed25e0ceabdf8379daca2

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.