OpenSearch SQL Cursor Pagination Unrestricted Deserialization RCE
CVE-2026-83497 Published on August 31, 2026

Unrestricted Java Deserialization in OpenSearch SQL Plugin Cursor Pagination
Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql endpoint.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-83497 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Type

What is a Marshaling, Unmarshaling Vulnerability?

The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

CVE-2026-83497 has been classified to as a Marshaling, Unmarshaling vulnerability or weakness.


Products Associated with CVE-2026-83497

stack.watch emails you whenever new vulnerabilities are published in Opensearch or Amazon Opensearch Service. Just hit a watch button to start following.

 
 

Affected Versions

OpenSearch: Amazon OpenSearch Service: