OpenSearch SQL Plugin - Async Query Validation Bypass
UnratedCVE-2026-18428 · Published Aug 13, 2026 · updated Sep 9, 2026
Bulletin ID: 2026-081-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/13/2026 10:30 AM PDT Description: OpenSearch SQL plugin is a plugin that enables SQL and PPL query capabilities on OpenSearch clusters, including direct query integration with external data sources via Apache Spark. An issue exists where the Flint extension query handler validates SQL queries without sufficient restrictions, allowing a user with async query access to bypass the SQL grammar deny list via the direct query endpoint. Affected Products & Versions: OpenSearch SQL Plugin (open-source, self-managed): - Affected: v2.13 to v3.6 - Fixed: versions 3.7 and 2.19.6 Amazon OpenSearch Service (AWS Managed): - Affected: v2.13 to v3.5 - Fixed: v2.13 to v3.5 (via service software update) Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Affected versions
Details and references
- Severity from
- no source yet
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 18 | Issue with Amazon ion-java - Memory-amplification denial of service | Unrated | No fix yet |
| Aug 18 | Uncontrolled resource consumption in OpenSearch Dashboards capabilities route | Unrated | No fix yet |
| Aug 12 | Out-of-bounds read in the Base64 decoder in the AWS SDK for C++ | Medium5.3 | 1.11.862 |
| Aug 12 | AWS: out-of-bounds write | Unrated | No fix yet |
| Aug 12 | Missing Input Validation in OpenSearch Security Analytics Plugin | Unrated | No fix yet |
| Aug 12 | Missing Authorization in OpenSearch Alerting Plugin | Unrated | No fix yet |