Missing Auth in OpenSearch Execute Monitor API Enables Data Manipulation
CVE-2026-19311 Published on August 12, 2026
Missing Authorization in Execute Monitor API in OpenSearch Alerting Plugin
Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.
Vulnerability Analysis
CVE-2026-19311 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Undefined Behavior for Input to API
The behavior of this function is undefined unless its control parameter is set to a specific value.
Products Associated with CVE-2026-19311
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-19311 are published in these products:
Affected Versions
AWS OpenSearch:- Version 2.4, <= 3.5 is affected.
- Version 2.4.0, <= 2.19.5 is affected.
- Version 3.0.0, <= 3.7.0 is affected.