bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: CVE-2026-19311

show all
Wednesday, August 12, 2026

OpenSearch Alerting Plugin: Authorization Bypass Requires Immediate Patching

OpenSearch Alerting Plugin has a nasty authorization flaw (CVE-2026-19311) that lets authenticated users with alerting_full_access role read, modify, or delete arbitrary index data through crafted monitor requests. Affected versions: 2.4.0–2.19.5 and 3.0.0–3.7.0 (self-managed), plus AWS OpenSearch Service domains on engines 2.4–3.5. Action required: upgrade to 2.19.6, 3.8.0, or service software R20260428-P3 immediately.

source: [aws/security-bulletin]