bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Thursday, August 13, 2026

OpenSearch Security Analytics Plugin: SSRF Vulnerability Requires Update

OpenSearch Security Analytics Plugin has a critical input validation flaw (CVE-2026-18952) that lets authenticated users perform server-side request forgery and read local files. If you're running plugin version 2.15.0 or later, you need to upgrade to 3.5.0 or newer. AWS managed domains are mostly safe since the vulnerable feature isn't enabled by default, but self-managed instances require immediate patching.

source: [aws/security-bulletin]