CVE-2026-18952 - Missing Input... Note

CVE-2026-18952 - Missing Input Validation in OpenSearch Security Analytics Plugin

This bulletin addresses CVE-2026-18952, a critical vulnerability in the OpenSearch Security Analytics plugin. The issue stems from missing input validation within the threat intelligence feed parser. An authenticated user with specific privileges can exploit this flaw to perform Server-Side Request Forgery (SSRF). This SSRF allows them to read local files by manipulating a URL parameter. The vulnerability affects self-managed OpenSearch Security Analytics plugins version 2.15.0 and later. For Amazon OpenSearch Service, domains running engine versions 2.15.0 and above are impacted. However, the affected functionality is not enabled by default in the AWS managed service. The vulnerability is fixed in OpenSearch Security Analytics plugin version 3.5.0 and later. Amazon OpenSearch Service has addressed this through service software updates for engine version 3.5. Users are advised to consult the linked article for complete details.