Junglewise Threat Intelligence

CVE-2026-19311: OpenSearch Alerting Plugin missing authorization

CVE-2026-19311 · Severity: high · CVSS 0 · Published 2026-09-09

Executive brief

A missing authorization vulnerability in the OpenSearch Alerting Plugin allows an attacker to perform unauthorized actions on alerting configurations without proper authentication checks. This could enable an attacker to create, modify, or delete alerts, potentially disrupting monitoring and notification systems that organizations rely on for operational visibility and incident detection.

Technical details

The OpenSearch Alerting Plugin contains a missing authorization vulnerability in its access control mechanism. The vulnerability allows an attacker to bypass authorization checks on alerting operations, including creating, reading, updating, and deleting alert configurations, potentially without requiring proper authentication. The attack is reachable over the network if the OpenSearch service is exposed or accessible within a network boundary. An attacker exploiting this flaw can manipulate alert configurations, disable critical monitoring, inject malicious alerts, or cause denial of service to alerting functionality. Patch availability should be verified through AWS security bulletins and OpenSearch project updates.

Affected products

  • AWS OpenSearch Alerting Plugin

Timeline

  • 2026-09-09: disclosed

References

Related threats