CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-18428

highCVSS 8.8covered by 2 sourcesfirst seen 2026-08-13
A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on Apache Spark workers by sending a crafted SQL query to the direct query endpoint.

CSIRTS triage

vendor: OpenSearchproduct: OpenSearch SQL PluginAuthentication bypassaffected: v2.13 to v3.6 (open-source); v2.13 to v3.5 (AWS managed)
What
SQL grammar deny list validation bypass in Flint extension query handler allowing users with async query access to bypass SQL restrictions.
Who is affected
OpenSearch SQL Plugin versions 2.13–3.6 self-managed, and AWS OpenSearch Service versions 2.13–3.5.
Urgency
High; authentication bypass allows unprivileged users to execute restricted queries.
Action
Upgrade to OpenSearch SQL Plugin v3.7 or v2.19.6, or apply AWS service software update for managed deployments.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-18428

Get an email if CVE-2026-18428 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-18428

CVE.org record

Embed the live status

CVE-2026-18428 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-18428 status](https://www.csirts.com/badge/CVE-2026-18428)](https://www.csirts.com/cve/CVE-2026-18428)