CVE-2026-18420 - Remote Code Execution via Prototype Pollution in OpenSearch Dashboards TSVB Plugin

Published 2026-09-09T21:30:11Z96e0aacf66ac303530d1cb30a1b85eb3cd747f8692b3742e900ed5e7bdc5ea82

Source metadata

Publication date
2026-09-09T21:30:11Z
Source identifier
29269334545db0f7e3891f34d6a3cd0e9b163364
Public record ID
record:sha256:96e0aacf66ac303530d1cb30a1b85eb3cd747f8692b3742e900ed5e7bdc5ea82

This is source-provided metadata, not an enriched summary or an impact assessment. Follow the canonical source link for the published material.

Evidence and limitations

Source ID
aws_security_bulletins
Record identifier
96e0aacf66ac303530d1cb30a1b85eb3cd747f8692b3742e900ed5e7bdc5ea82
Record type
Source metadata

This record may overlap with other records. Source metadata can be incomplete or change. Validate consequential decisions against the linked source and your own environment.