CVE-2026-84942 - Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards
Bulletin ID: 2026-102-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/08/2026 12:30 PM PDT
Description:
A stored cross-site scripting (XSS) issue in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization.
Affedted products & versions:
- OpenSearch Dashboards (open-source, self-managed)
- Affected:
v2.0.0, v2.1.0, v2.2.0, v2.3.0, v2.4.0, v2.5.0, v.2.6.0, v2.7.0, v2.8.0, v2.9.0, v2.10.0, v2.11.0, v2.12.0, v2.13.0, v2.14.0, v2.15.0, v2.16.0, v2.17.0, v2.18.0, v2.19.0, v3.0.0, v3.1.0, v3.2.0, v3.3.0, v3.4.0, v3.5.0
- Fixed:
v2.19.5 and v3.6.0 - Amazon OpenSearch Service (AWS Managed)
- Affected:
v2.3.0, v2.5.0, v2.7.0, v2.9.0, v2.11.0, v2.13.0, v2.15.0, v2.17.0, v2.19.0, v3.1.0, v3.3.0, v3.5.0
- Fixed:
v2.3.0, v2.5.0, v2.7.0, v2.9.0, v2.11.0, v2.13.0, v2.15.0, v2.17.0, v2.19.0 and v3.1.0, v3.3.0, v3.5.0 - Amazon OpenSearch Serverless
- Not affected
Resolution:
For OpenSearch (open-source), this issue has been addressed in OpenSearch Dashboards 2.19.5 and 3.6.0. We recommend upgrading to one of these versions or later, which includes additional hardening of Vega expression validation, and ensuring any forked or derivative code is patched to incorporate the new fixes.
For Amazon OpenSearch Service (managed), this issue has been addressed and patched in all affected versions. We recommend that customers update their domains to the latest service software version as soon as possible. No engine version upgrade is required. You can apply the update from the console by selecting your domain, choosing Actions, Service Software Version, then clicking Update. Domains with automatic software updates enabled receive this update during their next off-peak window with no action required. For full details, see Service software updates in Amazon OpenSearch Service.
Workarounds:
Because this issue requires dashboard/visualization write permissions to reproduce, restrict write access to the visualization and saved-object APIs to trusted users only. Optionally, disable the Vega visualization type. These measures reduce impact until the update is applied.
References:
Please email aws-security@amazon.com with any security questions or concerns.