CVE-2026-84942
Dashboard / Vulnerabilities / CVE-2026-84942
CVE-2026-84942
Summary: Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards
Details: Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function property nested inside an array to bypass validation.
References: https://aws.amazon.com/security/security-bulletins/2026-102-aws/, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84942.json, https://nvd.nist.gov/vuln/detail/CVE-2026-84942, https://github.com/opensearch-project/OpenSearch-Dashboards/releases/tag/2.19.5, https://github.com/opensearch-project/OpenSearch-Dashboards/releases/tag/3.6.0
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
