CVE-2026-19311- Missing Authorization in OpenSearch Alerting Plugin
Amazon OpenSearch ยท 2026-09-09
Actions
Technical Details
| Affected Versions | 2.4.0 through 2.19.5, 3.0.0 through 3.7.0 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-19311 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update OpenSearch Alerting Plugin to version 2.19.6 or 3.8.0 and Amazon OpenSearch Service to the latest service software version to address CVE-2026-19311, a missing authorization issue that could allow unauthorized data access and modifications.
For Platform Teams
Deploy the latest OpenSearch Alerting Plugin and Amazon OpenSearch Service updates to ensure robust security measures are in place, mitigating the risk of unauthorized data access and modifications due to CVE-2026-19311.
For Executives
Implement immediate updates to mitigate CVE-2026-19311, a critical security vulnerability in OpenSearch Alerting Plugin, to prevent unauthorized data access and modifications, ensuring data integrity and compliance.
Source
Related Amazon OpenSearch Updates
- CVE-2026-75897 - Uncontrolled resource consumption in OpenSearch Dashboards capabilities route (2026-09-09)
- CVE-2026-18428 - OpenSearch SQL Plugin - Async Query Validation Bypass (2026-09-09)
- CVE-2026-83497 - OpenSearch SQL Plugin - Unrestricted Java Deserialization in Cursor Pagination (2026-09-09)
- CVE-2026-18952 - Missing Input Validation in OpenSearch Security Analytics Plugin (2026-09-09)
- Amazon OpenSearch Service adds new Cluster Insights for faster diagnosis of cluster status (2026-08-31)