AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18952

HIGH · CVSS 8.1 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The OpenSearch Security Analytics plugin is vulnerable due to inadequate input validation in its threat intelligence feed parser, enabling authenticated remote users to exploit server-side request forgery (SSRF) vulnerabilities. This could allow attackers to read local files by manipulating URL parameters in the threat intel source configuration endpoint. Organizations using this plugin should prioritize remediation to mitigate potential data exposure risks.

CVE
CVE-2026-18952
Severity
HIGH
CVSS
8.1
EPSS
0.32%

Original NVD Description

Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint.