CVE-2026-19311: Aws Opensearch

High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.

Affected products

  • Aws Opensearch: from 2.4, up to and including 3.5
  • GitHub Opensearch: from 2.4.0, up to and including 2.19.5; from 3.0.0, up to and including 3.7.0

Published 2026-08-12. Last modified 2026-08-13.