HIGH 8.6 NVD
CVE-2026-19311
Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitr
Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.
References
- https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-opensearch-service-version-3-5/
- https://aws.amazon.com/security/security-bulletins/2026-078-aws/
- https://github.com/opensearch-project/alerting/security/advisories/GHSA-xxpg-q3wh-685q
This high severity vulnerability with a CVSS score of 8.6 was published on 2026-08-12 via NVD.
vulnfeed aggregates 10542 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.