CVE-2026-18420Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code execution.  To remediate this issue, users should upgrade to OpenSearch Dashboards 3.8 or later.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-20); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-20: 2Mentions · 2026-08-21: 1Patch / Workaround · 2026-08-21: 1Technical Details · 2026-08-20: 2Technical Details · 2026-08-21: 108-2008-21
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-202
Disclosure2
2026-08-211
Patch1
Full discourse3 posts
  • HOL@HashgraphOnline
    Patch

    CVE-2026-18420: OpenSearch Dashboards TSVB metrics API prototype-pollutes Object.prototype. An authenticated user with standard data access (not admin) can reach RCE. Affected: OSS and AWS Managed >=3.0.0 <3.8.0 Fix: upgrade to 3.8.0. Workaround: disable TSVB. https://hol.org/blog/cve-2026-18420-opensearch-dashboards-tsvb-prototype-pollution-rce

    Post summary

    The notice announces CVE‑2026‑18420, notes a prototype‑pollution RCE in OpenSearch Dashboards TSVB, and provides a fix (upgrade to 3.8.0) and a workaround (disable TSVB).

    6201902.0K
    19.6K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-18420 Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on th… https://www.cve.org/CVERecord?id=CVE-2026-18420 ----- Traducción: CVE-2026-18420 Val… https://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑18420, describing a code‑execution flaw in OpenSearch Dashboards TS VB plugin for authenticated users; no exploitation, patch, or PoC details are offered.

    0000023
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-18420 Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on th… https://www.cve.org/CVERecord?id=CVE-2026-18420

    Post summary

    The text announces CVE‑2026‑18420, describing an input validation flaw in OpenSearch Dashboards that permits authenticated users to run arbitrary code, but it lacks any proof‑of‑concept, exploit code, or mention of patches.

    000001.5K
    58.0K followersView on X

Explore more