
🚨High - OpenSearch SQL plugin Flint async query handler allows SQL validation bypass → RCE on Spark workers (CVE-2026-18428) The Flint extension query handler in the OpenSearch SQL plugin validates SQL with insufficient restrictions, letting an authenticated user with async query access bypass the SQL grammar deny list via the direct query endpoint. AWS describes the end impact as arbitrary code execution on the Apache Spark workers backing the async query engine. 👉Affected: OpenSearch SQL plugin v2.13–v3.6 | Fixed in 3.7 and 2.19.6. Amazon OpenSearch Service v2.13–v3.5 fixed via service software update
Post summary
The post describes a high‑severity RCE vulnerability in the OpenSearch SQL plugin due to a SQL validation bypass and notes that the issue is patched in newer versions and via a service update.

