CVE-2026-84942 - Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards

Published 2026-09-09T21:30:11Zd968a7e60abef1c2c699d3dd11bbe822fae4df39de3b032514aac40045462bfd

Source metadata

Publication date
2026-09-09T21:30:11Z
Source identifier
ee09ab7fd29f155e023ed25e0ceabdf8379daca2
Public record ID
record:sha256:d968a7e60abef1c2c699d3dd11bbe822fae4df39de3b032514aac40045462bfd

This is source-provided metadata, not an enriched summary or an impact assessment. Follow the canonical source link for the published material.

Evidence and limitations

Source ID
aws_security_bulletins
Record identifier
d968a7e60abef1c2c699d3dd11bbe822fae4df39de3b032514aac40045462bfd
Record type
Source metadata

This record may overlap with other records. Source metadata can be incomplete or change. Validate consequential decisions against the linked source and your own environment.

Record · CVE-2026-84942 - Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards · Baitaphish