🔴 Critical  |  Source: AWS Security Bulletins


A remote code execution vulnerability has been identified in the TSVB (Time Series Visual Builder) plugin within OpenSearch Dashboards, tracked as CVE-2026-18420. The flaw stems from prototype pollution, a JavaScript attack technique that allows an attacker to manipulate an application’s core objects and potentially execute arbitrary code on the server. This is significant for AWS customers running Amazon OpenSearch Service with Dashboards enabled, as exploitation could lead to full compromise of the Dashboards environment.

Security Architect’s Take: Review your Amazon OpenSearch Service domains immediately to determine whether OpenSearch Dashboards is publicly exposed or accessible to untrusted users, and apply any AWS-issued patches or version updates referenced in the full bulletin. As an interim control, consider restricting network access to Dashboards endpoints using resource-based policies, VPC configurations, or IP allowlisting until patched versions are confirmed in your environment.

Original advisory: CVE-2026-18420 - Remote Code Execution via Prototype Pollution in OpenSearch Dashboards TSVB Plugin