CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-18420

highCVSS 8.8covered by 2 sourcesfirst seen 2026-08-20
Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code execution. To remediate this issue, users should upgrade to OpenSearch Dashboards 3.8 or later.

CSIRTS triage

What
Improper input validation in Time Series Visual Builder (TSVB) plugin allows remote authenticated code execution via crafted JSON payload.
Who is affected
OpenSearch Dashboards users (self-managed and AWS-managed) on versions 3.0.0 through 3.7.x with standard data access permissions.
Urgency
Critical; authenticated RCE in widely-used visualization plugin requires immediate patching.
Action
Upgrade OpenSearch Dashboards to version 3.8.0 or later.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-18420

Get an email if CVE-2026-18420 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-18420

CVE.org record

Embed the live status

CVE-2026-18420 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-18420 status](https://www.csirts.com/badge/CVE-2026-18420)](https://www.csirts.com/cve/CVE-2026-18420)