Impact
The CVE describes a missing authorization check in the Execute Monitor API of the OpenSearch Alerting plugin. An authenticated user who can craft a monitor request is able to bypass the intended data source constraints and subsequently read, modify, or delete any index data. The flaw is rooted in CWE‑475, indicating insecure handling of data that permits unauthorized manipulation. Successful exploit would compromise the integrity and availability of monitored data and could provide a foothold for further privilege escalation by altering monitoring configurations.
Affected Systems
The vulnerability affects the Amazon OpenSearch Service (AWS:OpenSearch) and the community OpenSearch project (GitHub:OpenSearch) where the Alerting plugin is deployed. Specific version information is not listed in the CNA data, meaning any installation using the default plugin configuration prior to a patch might be vulnerable. System administrators should verify the Alerting plugin version in use and assess whether the affected functionality exists.
Risk and Exploitability
With a CVSS score of 8.6 the flaw is considered high severity. An EPSS score is unavailable, and the vulnerability is not currently listed in the CISA KEV catalogue, indicating no confirmed exploitation yet but leaving the theoretical risk high. An attacker would need legitimate cluster credentials and would exploit the exposed Execute Monitor API from outside the cluster. The high CVSS score coupled with the lack of mitigation measures means this vulnerability presents a significant risk to data confidentiality, integrity, and availability.
OpenCVE Enrichment