Search
Search Results (2 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-18952 | 2 Aws, Github | 2 Opensearch, Opensearch | 2026-08-12 | 8.1 High |
| Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint. | ||||
| CVE-2026-19311 | 2 Aws, Github | 2 Opensearch, Opensearch | 2026-08-12 | 8.1 High |
| Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters. | ||||
Page 1 of 1.