CVE-2026-18952
EUVD-2026-5742212.08.2026, 19:17
Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint.
Awaiting analysis
This vulnerability is currently awaiting analysis.