CVE-2026-19311CWE-475
CVE-2026-19311
High · published August 12, 2026
What it is
Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.
The record
Technical detail
- CVSS v3.1
- 8.1 · HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00415 · 34.7th percentile
- Weakness
- CWE-475 · Undefined Behavior for Input to API
- Published
- 2026-08-12T23:17Z
References (3)
EPSS history
Timeline