{"id":"CVE-2026-84942","summary":"Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards","details":"Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function property nested inside an array to bypass validation.","modified":"2026-09-10T03:48:29.806827354Z","published":"2026-09-08T19:41:25.224Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84942.json","cna_assigner":"AMZN","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://aws.amazon.com/security/security-bulletins/2026-102-aws/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84942.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84942"},{"type":"FIX","url":"https://github.com/opensearch-project/OpenSearch-Dashboards/releases/tag/2.19.5"},{"type":"FIX","url":"https://github.com/opensearch-project/OpenSearch-Dashboards/releases/tag/3.6.0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/opensearch-project/opensearch-dashboards","events":[{"introduced":"3d6dd638d021f383a4c6ab750c83a1d30d3787b3"},{"fixed":"bc90b6a50a0989323442aba09ffd2ff270d5340f"},{"fixed":"47091b2bb937be28e29cde7c3d2c3c9ee6803c27"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"v2.0.0"},{"last_affected":"v3.5.0"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84942.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N"}]}