CVE-2026-18952

Source
https://cve.org/CVERecord?id=CVE-2026-18952
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18952.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-18952
Aliases
  • GHSA-w946-8jxc-6v3m
Published
2026-08-12T18:42:38Z
Modified
2026-08-23T03:42:34Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Missing Input Validation in Threat Intel Feed Parser in OpenSearch Security Analytics Plugin
Details

Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint.

Database specific
{
    "cna_assigner": "AMZN",
    "cwe_ids": [
        "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18952.json"
}
References

Affected packages

Git / github.com/opensearch-project/security-analytics

Affected ranges

Type
GIT
Repo
https://github.com/opensearch-project/security-analytics
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.15.0"
        },
        {
            "fixed": "3.5.0"
        },
        {
            "fixed": "3.7.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18952.json"