Junglewise Threat Intelligence

CVE-2026-18428: OpenSearch SQL Plugin async query validation bypass

CVE-2026-18428 · Severity: high · Published 2026-09-09

Executive brief

The OpenSearch SQL Plugin enables SQL and PPL query capabilities on OpenSearch clusters. A validation bypass vulnerability allows users with async query access to circumvent SQL grammar restrictions via the direct query endpoint, potentially allowing unauthorized query execution or data exposure.

Technical details

The Flint extension query handler in OpenSearch SQL Plugin performs insufficient validation of SQL queries submitted through the direct query endpoint. An authenticated user with async query access can bypass the SQL grammar deny list by crafting specially-formed requests. The vulnerability exists in versions 2.13 through 3.6 of the open-source plugin and versions 2.13 through 3.5 of Amazon OpenSearch Service. This authentication requirement limits exposure to users with existing cluster access. Patches are available in OpenSearch SQL Plugin 3.7 and 2.19.6, and Amazon OpenSearch Service addresses the issue via service software updates.

Affected products

  • OpenSearch SQL Plugin 2.13 to 3.6 (open-source); 2.13 to 3.5 (AWS managed)
  • Amazon OpenSearch Service 2.13 to 3.5

Timeline

  • 2026-08-13: disclosed: AWS Security Bulletin 2026-081-AWS published
  • 2026-09-09: advisory: CVE-2026-18428 published

References

Related threats