OpenSearch Dashboards 3.8 TVBZ RCE via JSON (Prototype Pollution)
CVE-2026-18420 Published on August 20, 2026
RCE via Prototype Pollution in OpenSearch Dashboards
Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code execution.
To remediate this issue, users should upgrade to OpenSearch Dashboards 3.8 or later.
Vulnerability Analysis
CVE-2026-18420 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
What is a Prototype Pollution Vulnerability?
The software receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
CVE-2026-18420 has been classified to as a Prototype Pollution vulnerability or weakness.
Products Associated with CVE-2026-18420
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-18420 are published in these products:
Affected Versions
AWS Amazon OpenSearch Service:- Version 3.0.0 and below 3.8.0 is affected.
- Version 3.0.0 and below 3.8.0 is affected.