cvesecurityopensearch
CVE-2026-18420: OpenSearch Dashboards TSVB Prototype Pollution RCE
How to fix CVE-2026-18420: upgrade OpenSearch Dashboards to 3.8.0. Authenticated TSVB metrics JSON prototype pollution RCE. Affects OSS and AWS Managed >=3.0.0 <3.8.0.