CVE-2026-19311CWE-475

CVE-2026-19311

High · published August 12, 2026

CVSS v3.1
8.1
EPSS
0%
Percentile
34.7
In the wild
Unconfirmed
What it is

Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.

The record
Technical detail
CVSS v3.1
8.1 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00415 · 34.7th percentile
Weakness
CWE-475 · Undefined Behavior for Input to API
Published
2026-08-12T23:17Z
References (3)
EPSS history
Timeline
  • 12 AUG 18:34Z
    Missing Authorization in Execute Monitor API in OpenSearch Alerting Plugin
    cvelistv5