CVE-2026-84942 in Amazon and Opensearch Products
Published on September 8, 2026
Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards
Vulnerability Analysis
CVE-2026-84942 is exploitable with network access, requires user interaction and a small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is a XSS Vulnerability?
The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVE-2026-84942 has been classified to as a XSS vulnerability or weakness.
Products Associated with CVE-2026-84942
stack.watch emails you whenever new vulnerabilities are published in Amazon Aws or Opensearch Dashboards. Just hit a watch button to start following.
Affected Versions
AWS Amazon OpenSearch Service:- Version v2.3.0, <= v3.5.0 is unaffected.
- Version v2.0.0, <= v3.5.0 is affected.