CVE-2026-19311
Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.
- Published Aug 12, 2026
- CVSS 8.6 high
- 0.6% chance of exploitation in the next 30 days (EPSS)
Affected software
In the news
- CVE-2026-19311- Missing Authorization in OpenSearch Alerting Plugin AWS Security Bulletins ·