# CVE-2022-41918

## Summary

- **CVE ID:** CVE-2022-41918
- **Severity:** MEDIUM
- **CVSS Score:** 6.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)
- **CWE:** CWE-863, CWE-612
- **Published:** Nov 15, 2022
- **Last Modified:** Mar 13, 2026

## Description

OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. There is an issue with the implementation of fine-grained access control rules (document-level security, field-level security and field masking) where they are not correctly applied to the indices that back data streams potentially leading to incorrect access authorization. OpenSearch 1.3.7 and 2.4.0 contain a fix for this issue. Users are advised to update. There are no known workarounds for this issue.

## Affected Products

- opensearch-project — security (<1.3.7)
- opensearch-project — security (>= 2.0.0, < 2.4.0)

## References

- [CNA](https://github.com/opensearch-project/security/security/advisories/GHSA-wmx7-x4jp-9jgg)
- [CNA](https://github.com/opensearch-project/security/commit/f7cc569c9d3fa5d5432c76c854eed280d45ce6f4)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.19%
- **EPSS Percentile:** 40.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._