CVE-2026-18952
Last modified
CVE-2026-18952 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| AWS | Opensearch | >= 2.15.0, < 3.5.0 |
| Github | Opensearch | >= 2.15.0, < 3.7.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-18952?
How severe is CVE-2026-18952?
How do I fix CVE-2026-18952?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-18947A flaw was found in Feast. An authorization bypass vulnerabi…8.5
- CVE-2026-18948A flaw was found in Feast. The system improperly deserialize…9.9
- CVE-2026-18949A flaw was found in odh-dashboard. This vulnerability allows…8.8
- CVE-2026-1895A flaw has been found in WeKan up to 8.20. Affected is the f…6.3
- CVE-2026-18950A flaw was found in odh-dashboard. An authenticated user of …8.8
- CVE-2026-18951A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay…8.8
- CVE-2026-18953Improper limitation of a pathname to a restricted directory …8.8
- CVE-2026-18954Incorrect authorization in the aggregation pipeline tool in …5.7
- CVE-2026-18957Improper neutralization of input during web page generation …5.4
- CVE-2026-18958A vulnerability was detected in imranrisal-dev Student-Manag…7.3
- CVE-2026-18959A flaw has been found in yushine InnoShop up to 0.8.2. Affec…5.4
- CVE-2026-1896A vulnerability has been found in WeKan up to 8.20. Affected…6.3
Are you affected by CVE-2026-18952?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
