Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 10 Sep 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function property nested inside an array to bypass validation. | |
| Title | Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards | |
| First Time appeared |
Aws
Aws amazon Opensearch Service Opensearch Opensearch opensearch Dashboards |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:aws:amazon_opensearch_service:*:*:*:*:*:*:*:* cpe:2.3:a:opensearch:opensearch_dashboards:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Aws
Aws amazon Opensearch Service Opensearch Opensearch opensearch Dashboards |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-09-09T20:51:34.759Z
Reserved: 2026-09-02T16:47:56.353Z
Link: CVE-2026-84942
Updated: 2026-09-09T20:46:23.723Z
Status : Awaiting Analysis
Published: 2026-09-08T20:18:51.307
Modified: 2026-09-09T21:17:05.473
Link: CVE-2026-84942
No data.
OpenCVE Enrichment
Updated: 2026-09-09T14:15:11Z