CVE-2026-18952 - Missing Input Validation in OpenSearch Security Analytics Plugin
Amazon OpenSearch ยท 2026-09-09
Actions
Technical Details
| Affected Versions | >= 2.15.0 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-18952 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update OpenSearch Security Analytics Plugin to version >= 3.7.0 and apply the latest service software update for Amazon OpenSearch Service to address the missing input validation issue (CVE-2026-18952).
For Platform Teams
Deploy the updated OpenSearch Security Analytics Plugin and service software to enhance security posture and protect against potential SSRF attacks.
For Executives
Implement the latest security updates for OpenSearch to mitigate the risk of SSRF attacks and unauthorized file access, ensuring the protection of sensitive data and maintaining regulatory compliance.
Source
Related Amazon OpenSearch Updates
- CVE-2026-75897 - Uncontrolled resource consumption in OpenSearch Dashboards capabilities route (2026-09-09)
- CVE-2026-18428 - OpenSearch SQL Plugin - Async Query Validation Bypass (2026-09-09)
- CVE-2026-83497 - OpenSearch SQL Plugin - Unrestricted Java Deserialization in Cursor Pagination (2026-09-09)
- CVE-2026-19311- Missing Authorization in OpenSearch Alerting Plugin (2026-09-09)
- Amazon OpenSearch Service adds new Cluster Insights for faster diagnosis of cluster status (2026-08-31)