CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-18952

highCVSS 8.1covered by 2 sourcesfirst seen 2026-08-12
Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint.

CSIRTS triage

What
Missing input validation in threat intelligence feed parser allows authenticated users with specific roles to perform SSRF and read local files via crafted URL parameters.
Who is affected
OpenSearch Security Analytics Plugin v2.15.0+ and AWS OpenSearch Service domains running engine v2.15.0+.
Urgency
High; authenticated SSRF and file disclosure in security plugin poses significant data exposure risk.
Action
Upgrade to OpenSearch Security Analytics Plugin v3.5.0+ or apply AWS service software update for managed deployments.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-18952

Get an email if CVE-2026-18952 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-18952

CVE.org record

Embed the live status

CVE-2026-18952 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-18952 status](https://www.csirts.com/badge/CVE-2026-18952)](https://www.csirts.com/cve/CVE-2026-18952)