CVE-2026-18428 - OpenSearch SQL Plugin - Async Query Validation Bypass
Imported from official source
Bulletin ID: 2026-081-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/13/2026 10:30 AM PDT Description: OpenSearch SQL plugin is a plugin that enables SQL and PPL query capabilities on OpenSearch clusters, including direct query integration with external data sources via Apache Spark. An issue exists where the Flint extension query handler validates SQL queries without sufficient restrictions, allowing a user with async query access to bypass the SQL grammar deny list via the direct query endpoint. Affected Products & Versions: OpenSearch SQL Plugin (ope...
This version
- Version
- 1 of 2
- Recorded
- September 15, 2026 20:57
- Change
- Initial
- Content hash
85dafecc623e0313f9f802a2be3069e6- All versions
- Revision history