CVE-2026-19311- Missing Author... Note

CVE-2026-19311- Missing Authorization in OpenSearch Alerting Plugin

An important security bulletin has been issued regarding an authorization vulnerability in the OpenSearch Alerting plugin. This vulnerability, CVE-2026-19311, affects specific versions of both self-managed and Amazon OpenSearch Service deployments. An authenticated user with certain privileges could exploit this flaw to manipulate index data through crafted monitor requests. Mitigation involves updating to the fixed versions of the plugin or upgrading Amazon OpenSearch Service domains to the patched software release.