What is CVE-2026-19311?
The CVE-2026-19311 is a missing authorization flaw in the Execute Monitor API of the Amazon OpenSearch Alerting plugin. It could allow an authenticated remote user to read, modify, or delete arbitrary index data through a crafted request with unintended parameters. Affected users should update the plugin or review access controls to mitigate the risk.
Azərbaycanca: CVE-2026-19311 Amazon OpenSearch Alerting pluqininin Execute Monitor API-sində avtorizasiya yoxlanışının olmamasıdır. Bu, autentifikasiya olunmuş uzaq istifadəçiyə xüsusi hazırlanmış sorğu vasitəsilə ixtiyari indeks məlumatlarını oxumaq, dəyişdirmək və ya silmək imkanı verə bilər. Təsirə məruz qalan istifadəçilər pluqini son versiyaya yeniləməli və ya giriş nəzarətlərini nəzərdən keçirməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What operations can an attacker perform by exploiting the CVE-2026-19311 vulnerability?
An authenticated remote user could read, modify, or delete arbitrary index data through a crafted request.
What measures should be taken to mitigate the CVE-2026-19311 risk?
Affected users should update the Amazon OpenSearch Alerting plugin to the latest version or review their access controls.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.