CVE-2026-18428 - OpenSearch SQL Plugin - Async Query Validation Bypass
Amazon OpenSearch ยท 2026-09-09
Actions
Technical Details
| Affected Versions | v2.13 to v3.6 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-18428 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update OpenSearch SQL Plugin to versions 3.7 or 2.19.6 for open-source deployments and apply the latest service software update for Amazon OpenSearch Service to resolve the async query validation bypass vulnerability (CVE-2026-18428).
For Platform Teams
Deploy the patched versions of the OpenSearch SQL Plugin to ensure secure query handling and maintain the integrity of SQL query operations.
For Executives
Implement immediate updates to address the security vulnerability (CVE-2026-18428) in the OpenSearch SQL Plugin to mitigate risk and ensure data security.
Source
Related Amazon OpenSearch Updates
- CVE-2026-75897 - Uncontrolled resource consumption in OpenSearch Dashboards capabilities route (2026-09-09)
- CVE-2026-83497 - OpenSearch SQL Plugin - Unrestricted Java Deserialization in Cursor Pagination (2026-09-09)
- CVE-2026-18952 - Missing Input Validation in OpenSearch Security Analytics Plugin (2026-09-09)
- CVE-2026-19311- Missing Authorization in OpenSearch Alerting Plugin (2026-09-09)
- Amazon OpenSearch Service adds new Cluster Insights for faster diagnosis of cluster status (2026-08-31)