CVE-2026-19311
HIGH
8,6
Source: ff89ba41-3aa1-4d27-914a-91399e9639e5
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH
8,1
Source: ff89ba41-3aa1-4d27-914a-91399e9639e5
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: none
Description
AI Translation Available
Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.
475
Undefined Behavior for Input to API
IncompleteCommon Consequences
Security Scopes Affected:
Other
Potential Impacts:
Quality Degradation
Varies By Context
Applicable Platforms
All platforms may be affected
https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-opensearch-service-ve…
https://aws.amazon.com/security/security-bulletins/2026-078-aws/
https://github.com/opensearch-project/alerting/security/advisories/GHSA-xxpg-q3…