CVE-2026-18428 - OpenSearch SQ... Note

CVE-2026-18428 - OpenSearch SQL Plugin - Async Query Validation Bypass

An issue has been identified in the OpenSearch SQL plugin's Flint extension query handler where insufficient validation allows bypassing the SQL grammar deny list. This vulnerability can be exploited by users with async query access through the direct query endpoint. The affected versions range from v2.13 to v3.6 for the self-managed open-source plugin, and v2.13 to v3.5 for Amazon OpenSearch Service. Updates to versions 3.7 and 2.19.6 for the plugin, and a service software update for Amazon OpenSearch Service, address this vulnerability.