CVE-2026-18420: RCE via Prototype Pollution in OpenSearch Dashboards
Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code execution.
To remediate this issue, users should upgrade to OpenSearch Dashboards 3.8 or later.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenSearch Dashboards (TSVB plugin)to a version that resolves this vulnerability.Fixed in 3.8
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be an authenticated remote user. No user interaction is required, and exploitation uses a crafted JSON payload sent to the metrics visualization API endpoint.
Which component must be exposed for this vulnerability to be relevant?
The affected component is the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards. The vulnerable path is its metrics visualization API endpoint.
What should be done to remediate the issue?
Upgrade OpenSearch Dashboards to version 3.8 or later.