CVE-2026-18952 - Missing Input Validation in Threat Intel Feed Parser in OpenSearch Security Analytics Plugin
CVE ID :CVE-2026-18952
Published : Aug. 12, 2026, 6:42 p.m. | 46 minutes ago
Description :Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 12, 2026, 6:42 p.m. | 46 minutes ago
Description :Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...