CVE-2026-18428
Received
Received - Intake
SQL Query Validation Bypass in OpenSearch SQL Plugin
Vulnerability report for CVE-2026-18428, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-13
Last updated on: 2026-08-13
Assigner: AMZN
Description
Description
A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on Apache Spark workers by sending a crafted SQL query to the direct query endpoint.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| opensearch_project | opensearch_sql_plugin | From 2.13 (inc) to 3.6 (inc) |
| opensearch_project | opensearch_sql_plugin | 2.19.6 |
| opensearch_project | opensearch_sql_plugin | 3.7 |
| amazon | amazon_opensearch_service | From 2.13 (inc) to 3.5 (inc) |
| amazon | amazon_opensearch_service | 3.5 |
| opensearch | sql_plugin | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-693 | The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product. |