Retour à la veille

CVE-2026-19311

Publié : 12 août 2026
Modifié : 12 août 2026
Lien officiel NVD
Score CVSS
8.1
HIGH

Description détaillée

Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Références et Patchs