AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19311

HIGH · CVSS 8.1 EPSS 0.41% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Execute Monitor API in the Amazon OpenSearch Alerting plugin is vulnerable due to missing authorization, enabling authenticated remote users to manipulate index data by crafting specific inline monitor requests. This flaw could lead to unauthorized access, allowing attackers to read, modify, or delete sensitive data. Organizations utilizing Amazon OpenSearch should prioritize addressing this vulnerability to safeguard their data integrity and prevent potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19311
Severity
HIGH
CVSS
8.1
EPSS
0.41%

Original NVD Description

Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.