CVE-2026-18428: SQL Query Validation Bypass in OpenSearch Direct Query
A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on Apache Spark workers by sending a crafted SQL query to the direct query endpoint.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18428?
CVE-2026-18428 has a high severity rating of 8.8.
How do I fix CVE-2026-18428?
To mitigate CVE-2026-18428, ensure you update the OpenSearch SQL plugin to the latest version that addresses this vulnerability.
What impact does CVE-2026-18428 have?
CVE-2026-18428 allows a remote authenticated attacker to execute arbitrary code on Apache Spark workers due to SQL query validation bypass.
Who is affected by CVE-2026-18428?
CVE-2026-18428 affects users of the OpenSearch SQL plugin, specifically those utilizing the Flint extension query handler.
When was CVE-2026-18428 published?
CVE-2026-18428 was published on August 13, 2026.