Historical version

This is version 1, as it stood on . It is not what this organization currently publishes — read the current version.

CVE-2026-18952 - Missing Input Validation in OpenSearch Security Analytics Plugin

Amazon Web Services Version 1 original

Imported from official source

Bulletin ID: 2026-079-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/12/2026 11:45 AM PDT Description: OpenSearch is a community-driven, open-source search and analytics suite. We identified CVE-2026-18952, a missing input validation issue in the threat intelligence feed parser of the OpenSearch Security Analytics plugin. This issue may allow an authenticated user with the security_analytics_full_access role to perform server-side request forgery (SSRF) and read local files via a crafted URL parameter to the threat intel source configuration endpoint. Impac...

This version

Version
1 of 2
Recorded
September 15, 2026 20:57
Change
Initial
Content hash
61dc7b38bc68e516d535a4d937e4e90c
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.