CVE-2026-84942 - Stored Cross-... Note

CVE-2026-84942 - Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards

A critical stored cross-site scripting vulnerability has been identified in OpenSearch Dashboards. This issue resides within the Vega expression function implementation. A remote, authenticated attacker with write permissions to dashboards can exploit this flaw. By saving a malicious Vega visualization, the attacker can inject and execute arbitrary JavaScript. This script will then run within the browser context of other users viewing the dashboard. The vulnerability affects numerous versions of self-managed OpenSearch Dashboards, specifically from v2.0.0 up to v3.5.0. For self-managed instances, versions v2.19.5 and v3.6.0 have been released to address this vulnerability. Amazon OpenSearch Service, the AWS managed offering, is also impacted across various versions. The affected managed versions range from v2.3.0 to v3.5.0. Importantly, Amazon OpenSearch Serverless is not susceptible to this particular threat. Users are strongly advised to consult the provided article for comprehensive details.