
CVE-2026-18420: OpenSearch Dashboards TSVB metrics API prototype-pollutes Object.prototype. An authenticated user with standard data access (not admin) can reach RCE. Affected: OSS and AWS Managed >=3.0.0 <3.8.0 Fix: upgrade to 3.8.0. Workaround: disable TSVB. https://hol.org/blog/cve-2026-18420-opensearch-dashboards-tsvb-prototype-pollution-rce
Post summary
The notice announces CVE‑2026‑18420, notes a prototype‑pollution RCE in OpenSearch Dashboards TSVB, and provides a fix (upgrade to 3.8.0) and a workaround (disable TSVB).


