{"id":"CVE-2026-84942","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-84942","summary":"Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary…","details":"Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function property nested inside an array to bypass validation.","published":"2026-09-08T20:18:51.307","modified":"2026-09-08T20:18:51.307","cvss":{"score":8.7,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://aws.amazon.com/security/security-bulletins/2026-102-aws/"},{"type":"WEB","url":"https://github.com/opensearch-project/OpenSearch-Dashboards/releases/tag/2.19.5"},{"type":"WEB","url":"https://github.com/opensearch-project/OpenSearch-Dashboards/releases/tag/3.6.0"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-08T20:18:51.307"}}