CVE-2026-18428General

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on Apache Spark workers by sending a crafted SQL query to the direct query endpoint.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-693

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-14); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-14: 1Mentions · 2026-08-17: 1Patch / Workaround · 2026-08-17: 1Technical Details · 2026-08-14: 1Technical Details · 2026-08-17: 108-1408-17
Signal classification2 categories
General
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-08-141
General1
2026-08-171
Patch1
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - OpenSearch SQL plugin Flint async query handler allows SQL validation bypass → RCE on Spark workers (CVE-2026-18428) The Flint extension query handler in the OpenSearch SQL plugin validates SQL with insufficient restrictions, letting an authenticated user with async query access bypass the SQL grammar deny list via the direct query endpoint. AWS describes the end impact as arbitrary code execution on the Apache Spark workers backing the async query engine. 👉Affected: OpenSearch SQL plugin v2.13–v3.6 | Fixed in 3.7 and 2.19.6. Amazon OpenSearch Service v2.13–v3.5 fixed via service software update

    Post summary

    The post describes a high‑severity RCE vulnerability in the OpenSearch SQL plugin due to a SQL validation bypass and notes that the issue is patched in newer versions and via a service update.

    0000097
    291 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-18428 Arbitrary Code Execution in OpenSearch SQL Plugin via SQL Query Validation Bypass https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-18428

    Post summary

    The text briefly lists CVE‑2026‑18428, describing it as an arbitrary code execution vulnerability in the OpenSearch SQL Plugin, but offers no evidence of PoC, exploitation tools, active attacks, or patches.

    00000126
    4.1K followersView on X

Explore more