Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-12 19:17
Updated : 2026-08-21 19:17
NVD link : CVE-2026-18952
Mitre link : CVE-2026-18952
CVE.ORG link : CVE-2026-18952
JSON object : View
Products Affected
No product.
CWE
CWE-918
Server-Side Request Forgery (SSRF)
