CVE-2026-18428
SQL Query Validation Bypass in OpenSearch Direct Query
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on Apache Spark workers by sending a crafted SQL query to the direct query endpoint.
| CWE | CWE-693 |
| Vendor | aws |
| Product | opensearch |
| Published | Aug 13, 2026 |
| Last Updated | Aug 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for aws opensearch
Be the first to know when new high vulnerabilities affecting aws opensearch are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
AWS / Opensearch
2.13 โค 3.5
Github / Opensearch
2.13 โค 3.6
References
opensearch.org: https://opensearch.org/artifacts/by-version/?_gl=1*d14pqp*_up*MQ..*_ga*Nzc5NTAxNzM2LjE3ODM1NTA2NDA.*_ga_BQV14XK08F*czE3ODM1NTA2NDAkbzEkZzEkdDE3ODM1NTA3MTQkajU2JGwwJGg3NTc4ODY0OTM.#release-3-7-0 opensearch.org: https://opensearch.org/artifacts/by-version/?_gl=1*d14pqp*_up*MQ..*_ga*Nzc5NTAxNzM2LjE3ODM1NTA2NDA.*_ga_BQV14XK08F*czE3ODM1NTA2NDAkbzEkZzEkdDE3ODM1NTA3MTQkajU2JGwwJGg3NTc4ODY0OTM.#release-2-19-6 docs.aws.amazon.com: https://docs.aws.amazon.com/opensearch-service/latest/developerguide/service-software.html github.com: https://github.com/opensearch-project/sql/security/advisories/GHSA-g4jr-343c-fvjm aws.amazon.com: https://aws.amazon.com/security/security-bulletins/2026-081-aws/