CVE-2026-18952
Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint.
- Published Aug 12, 2026
- CVSS 8.6 high
- 0.5% chance of exploitation in the next 30 days (EPSS)
Affected software
In the news
- CVE-2026-18952 - Missing Input Validation in OpenSearch Security Analytics Plugin AWS Security Bulletins ·