AWS OpenSearch

3 known vulnerabilities in AWS OpenSearch, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-18428 CVSS 8.7 high A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with…
  • CVE-2026-19311 CVSS 8.6 high Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read…
  • CVE-2026-18952 CVSS 8.6 high Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated…