CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-19311

highCVSS 8.1covered by 2 sourcesfirst seen 2026-08-12
Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.

CSIRTS triage

What
Missing authorization in the Execute Monitor API allows authenticated users with alerting_full_access role to read, modify, or delete arbitrary index data via crafted inline monitor requests.
Who is affected
Users running OpenSearch Alerting Plugin versions 2.4.0 through 2.19.5 or 3.0.0 through 3.7.0, and AWS OpenSearch Service domains running engine versions 2.4 through 3.5.
Urgency
Moderate; unpatched vulnerable versions allow privilege misuse by authenticated users with a specific role to access and modify sensitive data.
Action
Upgrade OpenSearch Alerting Plugin to version 2.19.6 or 3.8.0, or apply AWS OpenSearch Service software update R20260428-P3 or later.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-19311

Get an email if CVE-2026-19311 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-19311

CVE.org record

Embed the live status

CVE-2026-19311 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-19311 status](https://www.csirts.com/badge/CVE-2026-19311)](https://www.csirts.com/cve/CVE-2026-19311)