CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-18952 - Missing Input Validation in OpenSearch Security Analytics Plugin

unknownCVE-2026-18952
Bulletin ID: 2026-079-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/12/2026 11:45 AM PDT Description: OpenSearch is a community-driven, open-source search and analytics suite. We identified CVE-2026-18952, a missing input validation issue in the threat intelligence feed parser of the OpenSearch Security Analytics plugin. This issue may allow an authenticated user with the security_analytics_full_access role to perform server-side request forgery (SSRF) and read local files via a crafted URL parameter to the threat intel source configuration endpoint. Impacted Versions: OpenSearch Security Analytics Plugin (open-source, self-managed): - Affected: >= 2.15.0 - Fixed: >= 3.5.0 Amazon OpenSearch Service (AWS Managed): - Affected: Domains running engine versions >= 2.15.0 - Fixed: Addressed via service software update for engine version 3.5. The affected functionality is not enabled in the default service configuration. Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

CSIRTS triage

What
Missing input validation in threat intelligence feed parser allows authenticated users with specific roles to perform SSRF and read local files via crafted URL parameters.
Who is affected
OpenSearch Security Analytics Plugin v2.15.0+ and AWS OpenSearch Service domains running engine v2.15.0+.
Urgency
High; authenticated SSRF and file disclosure in security plugin poses significant data exposure risk.
Action
Upgrade to OpenSearch Security Analytics Plugin v3.5.0+ or apply AWS service software update for managed deployments.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch OpenSearch Security Analytics Plugin

Get an email when a new OpenSearch Security Analytics Plugin advisory drops — max one per day, one-click unsubscribe.

Details

Source
AWS Security Bulletins (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-08-20
Exploitation
Not in CISA KEV at last sync

Original advisory: https://aws.amazon.com/security/security-bulletins/rss/2026-079-aws/

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-18952coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for - Missing Input

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from AWS Security Bulletins