CVE-2026-18428 - OpenSearch SQL Plugin - Async Query Validation Bypass

Published 2026-09-09T21:30:11Z4ba0e8e6918d6693eb15b9c89bcb6871fe08783b8056c4c8bfec7b0cd10eb776

Source metadata

Publication date
2026-09-09T21:30:11Z
Source identifier
f1a634096774febc8f12f0f6e0cb5a6fdafc873a
Public record ID
record:sha256:4ba0e8e6918d6693eb15b9c89bcb6871fe08783b8056c4c8bfec7b0cd10eb776

This is source-provided metadata, not an enriched summary or an impact assessment. Follow the canonical source link for the published material.

Evidence and limitations

Source ID
aws_security_bulletins
Record identifier
4ba0e8e6918d6693eb15b9c89bcb6871fe08783b8056c4c8bfec7b0cd10eb776
Record type
Source metadata

This record may overlap with other records. Source metadata can be incomplete or change. Validate consequential decisions against the linked source and your own environment.